Malware

Troj/Urelas-AU removal guide

Malware Removal

The Troj/Urelas-AU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Urelas-AU virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Urelas-AU?


File Info:

name: 4394286F33C231D31BDE.mlw
path: /opt/CAPEv2/storage/binaries/4a9aaa5043e76410dea4c1436bee76c8ce4800604b0e58b1b5d80f7a7c9ce5b6
crc32: C434B7BB
md5: 4394286f33c231d31bde4de89875fe9d
sha1: bb7c737134674f83ec819edea7c8a4be7fa938ba
sha256: 4a9aaa5043e76410dea4c1436bee76c8ce4800604b0e58b1b5d80f7a7c9ce5b6
sha512: bf13bda00e312c6bcff332f68de8541e69d5927e8b617486e6a7d64602ff2d69e4da285305ad8790f1aaefbba7c56d3cf5aeedd4403d4d0f4ce4ad16f164b58f
ssdeep: 1536:E49IoH+qGPLCEMWbImFe7fGfWXfpf3LmwmbvjUgfOGCj50hOsUJlol:VH+TPLCEM7mIVPL2boSCj50hOsU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171156C317781C032C09510358667C7B38A3DBD316BA4995BB788EB6E6F313D0EA3635A
sha3_384: f7d80f9c5a158be3eeca352221c66026e0de2c9a0256e2017beb2da80057947f3cf32d76e2124a426b66e93694eae3c2
ep_bytes: e8db640000e979feffff8bff558bec81
timestamp: 2012-10-31 14:58:54

Version Info:

CompanyName: Microsoft Corperation
FileDescription: Generic Host Process for Win32 Services
FileVersion: 1, 0, 1, 25
InternalName: Install.exe
LegalCopyright: Copyright (c) Microsoft. All rights reserved.
OriginalFilename: Install.exe
ProductName: Microsoft Windows Operating System
ProductVersion: 1, 0, 1, 25
Translation: 0x0412 0x04b0

Troj/Urelas-AU also known as:

LionicTrojan.Win32.Swisyn.lEAr
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
Cylanceunsafe
ZillyaTrojan.Generic.Win32.850101
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0048c2c71 )
K7GWTrojan ( 0048c2c71 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Rootkit.Agent.s
CyrenW32/Urelas.DO.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Urelas.R
APEXMalicious
ClamAVWin.Trojan.Barys-9754805-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Heur.Mint.SP.Urelas.1
NANO-AntivirusTrojan.Win32.Swisyn.csiwzp
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Urelas.ha
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
F-SecureTrojan.TR/Crypt.FKM.Gen
DrWebTrojan.DownLoader7.27838
VIPREGen:Heur.Mint.SP.Urelas.1
TrendMicroTROJ_GEN.R002C0DEN23
McAfee-GW-EditionBehavesLike.Win32.Infected.cz
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.4394286f33c231d3
SophosTroj/Urelas-AU
IkarusTrojan.Win32.Gupboot
GDataGen:Heur.Mint.SP.Urelas.1
JiangminTrojan.Generic.dlwxq
AviraTR/Crypt.FKM.Gen
Antiy-AVLTrojan/Win32.Swisyn
ArcabitTrojan.Mint.SP.Urelas.1
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
MicrosoftTrojan:Win32/Urelas.AA
GoogleDetected
AhnLab-V3Trojan/Win32.PbBot.R42541
Acronissuspicious
McAfeeGeneric Malware.mt
MAXmalware (ai score=87)
VBA32BScope.Trojan.Downloader
MalwarebytesBanker.Trojan.Stealer.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEN23
RisingTrojan.Urelas!1.9D87 (CLASSIC)
YandexTrojan.Swisyn!NaOf4OcoGEI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Urelas.D!tr
BitDefenderThetaGen:NN.ZexaF.36196.2m3@aKOWcXeO
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.f33c23
DeepInstinctMALICIOUS

How to remove Troj/Urelas-AU?

Troj/Urelas-AU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment