Malware

Troj/Urelas-AS removal guide

Malware Removal

The Troj/Urelas-AS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Urelas-AS virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Troj/Urelas-AS?


File Info:

name: 799B2907F5AB3C99CDD1.mlw
path: /opt/CAPEv2/storage/binaries/7be33e7bb95c6d80deb46b7eaa26ee1f33e7037899020957b916e1ca3f8c2ec2
crc32: 88A56492
md5: 799b2907f5ab3c99cdd1a5180886af8a
sha1: b1fc690fe56a1d128be70d96ecf4d827674026ee
sha256: 7be33e7bb95c6d80deb46b7eaa26ee1f33e7037899020957b916e1ca3f8c2ec2
sha512: 71ee40c722a08dd1cd8f30943f45f834f76856d1f45e96909c8dbb312b1d15bd9bae8510fc57e3c1ea9a0d0a360e958f739ada1defaab5b7e67855683032bcd5
ssdeep: 1536:iADe0Wbt1931D2P7BWLQ4zR4LUKMcPHFE3HP/G8j65CGE8ppR:iADe0Wc7UJ6LZMaHkj65DEGpR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170D3F61176408471F3590B324916EAE14969AC3D1AE4F98FF7787E3A5E322C39A7324F
sha3_384: 336e67e3a57696f8cdb83978b5560e4b44e87587ac336e9cd27dc1e68017b352cfb01374ac8f16d7d4b48685be40e304
ep_bytes: e819520000e979feffff8bff558bec8b
timestamp: 2014-06-05 06:54:42

Version Info:

0: [No Data]

Troj/Urelas-AS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Plite.4!c
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
ClamAVWin.Malware.Urelas-6717394-0
CAT-QuickHealTrojan.Beaugrit.14262
McAfeePWS-FBQQ!799B2907F5AB
Cylanceunsafe
VIPREGen:Heur.Mint.SP.Urelas.1
SangforWorm.Win32.Save.a
K7AntiVirusBackdoor ( 0053e8561 )
AlibabaBackdoor:Win32/Urelas.2ee0
K7GWBackdoor ( 0053e8561 )
Cybereasonmalicious.fe56a1
BaiduWin32.Trojan.Urelas.a
VirITTrojan.Win32.Generic.ECB
CyrenW32/Urelas.DE.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Urelas.U
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Plite.bhtr
BitDefenderGen:Heur.Mint.SP.Urelas.1
NANO-AntivirusTrojan.Win32.Urelas.kbmpfg
AvastWin32:BackdoorX-gen [Trj]
TencentTrojan.Win32.Urelas.16000161
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebBackDoor.Golf.196
ZillyaTrojan.Urelas.Win32.9044
McAfee-GW-EditionBehavesLike.Win32.Dropper.cm
FireEyeGeneric.mg.799b2907f5ab3c99
SophosTroj/Urelas-AS
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.111SHMK
JiangminTrojan/GenericCryptor.bt
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Urelas
Kingsoftmalware.kb.a.974
XcitiumTrojWare.Win32.Urelas.SH@5674sp
ArcabitTrojan.Mint.SP.Urelas.1
ZoneAlarmBackdoor.Win32.Plite.bhtr
MicrosoftTrojan:Win32/Urelas!atmnm
GoogleDetected
AhnLab-V3Trojan/Win32.Urelas.R149212
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36738.iuX@aeMIvCmi
VBA32SScope.Backdoor.Urelas.3114
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.Urelas!1.BE13 (CLASSIC)
YandexTrojan.Agent!raykctppMIM
IkarusTrojan.Win32.Beaugrit
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Urelas.U!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Troj/Urelas-AS?

Troj/Urelas-AS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment