Malware

About “Ursu.9054” infection

Malware Removal

The Ursu.9054 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.9054 virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Behavior consistent with a dropper attempting to download the next stage.
  • Anomalous binary characteristics

Related domains:

thatsawesome.top
duckandbear.top

How to determine Ursu.9054?


File Info:

crc32: D76756F7
md5: 8eef0cbdbeec652da77aeb5c5364e71f
name: 8EEF0CBDBEEC652DA77AEB5C5364E71F.mlw
sha1: c1946a7af25749c1afcabaed32bd33118f9e1bf8
sha256: dcbd68f977a906c79ef7fe902a3b28f25ce84eaee6148ccd9aecbc7f3a49ffbe
sha512: 4a582eccf0b6cba3d3f6262a574d7c7f30899a0d227c2acdea66f4ea9f08238ec35bf8eeee835bc69bbcf52685aaf505fb2cb5e4cea2f4d61c82f7f2c3bc2ace
ssdeep: 3072:AND7V2BCDm6Ltzu0pDes/8Wnroukw07Pt6UZT/X0J3KQsp82nYKBQ/qUFRm63CkC:Ar2R6xj18Wnrouk1Tt6ULO/25eFEkGFx
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: oGrimm Stone Prod. All rights reserved.
InternalName: myGrimm Installer
FileVersion: 12.8.2.9
CompanyName:
Comments: xInstall software
ProductName: iNSIS installer
ProductVersion: 21.8.2.9
Translation: 0x0409 0x04b0

Ursu.9054 also known as:

MicroWorld-eScanGen:Variant.Ursu.9054
FireEyeGeneric.mg.8eef0cbdbeec652d
McAfeeArtemis!8EEF0CBDBEEC
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 0051921e1 )
BitDefenderGen:Variant.Ursu.9054
K7GWTrojan-Downloader ( 0051921e1 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Taterf.A!Generic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Tovkater-6664559-0
KasperskyTrojan-Downloader.Win32.Tovkater.bou
NANO-AntivirusTrojan.Win32.Tovkater.etrahp
Ad-AwareGen:Variant.Ursu.9054
SophosMal/Generic-S (PUA)
ComodoMalware@#1vi36pe92hoff
DrWebTrojan.InstallMonster.2400
ZillyaAdware.DLBoost.Win32.3351
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftGen:Variant.Ursu.9054 (B)
SentinelOneStatic AI – Malicious PE – Downloader
GDataGen:Variant.Ursu.9054
JiangminTrojanDownloader.Tovkater.ai
AviraHEUR/AGEN.1117983
MAXmalware (ai score=99)
Antiy-AVLTrojan[Downloader]/Win32.Tovkater
ArcabitTrojan.Ursu.D235E
SUPERAntiSpywareAdware.Generic/Variant
ZoneAlarmHEUR:Trojan-Downloader.Win32.Tovkater.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Tovkater.R210632
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34804.jmKfaWlCMjoG
ALYacGen:Variant.Ursu.9054
VBA32Trojan.InstallMonster
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
ESET-NOD32multiple detections
YandexTrojan.DL.Tovkater!MhEfGkGs7eU
IkarusTrojan.Krypt
FortinetW32/Tovkater.FQ!tr
AVGWin32:Malware-gen
Cybereasonmalicious.dbeec6

How to remove Ursu.9054?

Ursu.9054 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment