Malware

Heur.Mint.SP.Urelas.1 removal tips

Malware Removal

The Heur.Mint.SP.Urelas.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Mint.SP.Urelas.1 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Heur.Mint.SP.Urelas.1?


File Info:

crc32: CB1C59D9
md5: 9c50bca3e00471cfee9f938e0fb367e3
name: 9C50BCA3E00471CFEE9F938E0FB367E3.mlw
sha1: a04354c7629e96b993fc2c041121413d8cca7c96
sha256: 4dea8cf94bf060f8f0f81b685ca0e45137581107195c2ce034fa4c16cd438790
sha512: b870838a83aa95991ab74a640a077a4a856f3c8005a0466aef3d52a04d6f9504527010c4088799adccab7b71c94ddcf60a72538d4a098dee3565174f84b6cc46
ssdeep: 12288:j/fCEOMsm8nc3qWQ8wqKhb43nLl5tDrXlFg:j/D0caF8wvhb43pDbg
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Heur.Mint.SP.Urelas.1 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
CAT-QuickHealTrojan.Gupboot.G.mue
Qihoo-360Win32/Trojan.87d
McAfeeBackDoor-FBLQ!9C50BCA3E004
CylanceUnsafe
VIPRETrojan.Win32.Urelas.o (v)
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 0053e8561 )
BitDefenderGen:Heur.Mint.SP.Urelas.1
K7GWTrojan ( 0047e3691 )
Cybereasonmalicious.3e0047
BaiduWin32.Trojan.Urelas.a
CyrenW32/Trojan.CDN.gen!Eldorado
SymantecBackdoor.Matsnu.B
APEXMalicious
AvastWin32:BackdoorX-gen [Trj]
KasperskyTrojan-Ransom.Win32.GenericCryptor.cys
AlibabaMalware:Win32/Dorpal.ali1000029
NANO-AntivirusTrojan.Win32.AVKill.cqkwqf
RisingRansom.GenericCryptor!8.2E88 (TFE:dGZlOgVTmfUzVyylBw)
Ad-AwareGen:Heur.Mint.SP.Urelas.1
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
ComodoTrojWare.Win32.Gupboot.BB@53dg1h
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.AVKill.33553
ZillyaTrojan.Urelas.Win32.1046
TrendMicroTrojan.Win32.Urelas.SM
McAfee-GW-EditionBehavesLike.Win32.Backdoor.hh
FireEyeGeneric.mg.9c50bca3e00471cf
SophosMal/Generic-R + Troj/Urelas-I
IkarusTrojan.Win32.Urelas
JiangminBackdoor/Plite.ae
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=80)
Antiy-AVLTrojan[Ransom]/Win32.GenericCryptor
MicrosoftTrojan:Win32/Urelas.AA
ArcabitTrojan.Mint.SP.Urelas.1
ZoneAlarmTrojan-Ransom.Win32.GenericCryptor.cys
GDataGen:Heur.Mint.SP.Urelas.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/RL.GenericCryptor.R243752
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.FmX@au1nAXjO
TACHYONRansom/W32.Agent.520974
VBA32BScope.Trojan.AVKill
MalwarebytesUrelas.Spyware.Stealer.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Urelas.S
TrendMicro-HouseCallTrojan.Win32.Urelas.SM
TencentTrojan.Win32.Agent.aep
YandexTrojan.GenAsa!sUuwzi5+TfM
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Urelas.U!tr
AVGWin32:BackdoorX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Heur.Mint.SP.Urelas.1?

Heur.Mint.SP.Urelas.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment