Malware

How to remove “Ursu.8578”?

Malware Removal

The Ursu.8578 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.8578 virus can do?

  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.8578?


File Info:

crc32: B0E8AA0C
md5: 5477a54bd3636ac9d586d3346c5e1c28
name: 5477A54BD3636AC9D586D3346C5E1C28.mlw
sha1: 5b57fdd501a63c5f50c1268bfa645e475a7459a8
sha256: 1df0175fc33a94efef739ad712e49417446fe98eb2848a6c60233c8e1e81db95
sha512: 31ee05ad165c293bb1513512d7686ad63c7b94a02f1ec3a0baebc3121500ed80d279abab3a0553e045f70278769d4ddce60eaf9de0c1c39c0edbd2a30b2b3bab
ssdeep: 768:n48Yrt9l9l7gubquo4DgKuChPiL6VYqJ/GDpsuGputlYVxouGjsylcON75b7avOa:jYrPlD71Ouo4B6JqUtsuGpjku+yONli
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: ColdCreekProd. All rights reserved.
InternalName: ColdCreekInstaller
FileVersion: 3.1.0.1
CompanyName: ColdCreekProd
Comments: Files installer
ProductName: Free files installer
ProductVersion: 3.1.0.1
FileDescription: Free files installer
Translation: 0x0409 0x04b0

Ursu.8578 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan-Downloader ( 00518e881 )
LionicTrojan.Win32.Tovkater.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.8578
CylanceUnsafe
SangforTrojan.Win32.Tovkater.gen
AlibabaTrojanDownloader:Win32/Tovkater.895f46dd
K7GWTrojan-Downloader ( 00518e881 )
Cybereasonmalicious.bd3636
SymantecTrojan.Gen.2
ESET-NOD32Win32/TrojanDownloader.Tovkater.EX
APEXMalicious
AvastWin32:Adware-gen [Adw]
KasperskyHEUR:Trojan-Downloader.Win32.Tovkater.gen
BitDefenderGen:Variant.Ursu.8578
MicroWorld-eScanGen:Variant.Ursu.8578
TencentWin32.Trojan-downloader.Tovkater.Suxr
Ad-AwareGen:Variant.Ursu.8578
SophosGeneric ML PUA (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Downloader.kc
FireEyeGeneric.mg.5477a54bd3636ac9
EmsisoftApplication.Downloader (A)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Occamy.C
GDataGen:Variant.Ursu.8578
AhnLab-V3PUP/Win32.BundleInstaller.R209982
Acronissuspicious
McAfeeArtemis!5477A54BD363
MAXmalware (ai score=95)
VBA32TrojanDownloader.Tovkater
MalwarebytesAdware.InstallMonster
PandaTrj/Genetic.gen
YandexTrojan.DL.Tovkater!KcYoe/d37Tk
IkarusTrojan-Downloader.Win32.Tovkater
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Ursu.8578?

Ursu.8578 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment