Trojan

What is “Trojan:Win32/Urelas.EC!MTB”?

Malware Removal

The Trojan:Win32/Urelas.EC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas.EC!MTB virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas.EC!MTB?


File Info:

name: 650C04386DC7EE0EE0DA.mlw
path: /opt/CAPEv2/storage/binaries/8730b59454b9c64c8a074c9450f76bce6389231111e5b685416919fd18937f3d
crc32: 91731653
md5: 650c04386dc7ee0ee0daa7cdd282fa8b
sha1: 6464f63ea729c0a194704e8803bf8a3445065077
sha256: 8730b59454b9c64c8a074c9450f76bce6389231111e5b685416919fd18937f3d
sha512: 9382cb46d28d4fb4fb1df1f67abd8071fa77bd4bdcb502e7789befff2e074db77715e304aabf4ff65e4aebff3bb73ca5b44742121060fc39f47b1489100848ef
ssdeep: 6144:L/FevhQgnGFlv+aTd+SRaL4kimVj0sQISzqJYpY:E5QyulnTd9Rabi6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FFE46B2076808072E36907300467E6E50A6D6E3A27A5E5CFF6787E356E713E35B3724E
sha3_384: 02055c4a708529b6319747caa5e4623dc99fbb5dd0ec492d0522d2bc0f092f85885efc560117dea6c9158e3eb64fe5fe
ep_bytes: 470383ee01c1e90283ef0183f90872b2
timestamp: 2013-09-03 01:49:14

Version Info:

0: [No Data]

Trojan:Win32/Urelas.EC!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.CardSpy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.467824
FireEyeGeneric.mg.650c04386dc7ee0e
SkyhighBehavesLike.Win32.Generic.jt
McAfeeGenericRXVS-VG!650C04386DC7
Cylanceunsafe
VIPREGen:Variant.Zusy.467824
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Zusy.467824
K7GWTrojan ( 005a4eb91 )
K7AntiVirusTrojan ( 005a4eb91 )
BitDefenderThetaGen:NN.ZexaF.36792.PmZ@aycbZGe
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.AZU
APEXMalicious
ClamAVWin.Malware.Wacatac-9770178-0
AlibabaTrojan:Win32/Urelas.08062ff5
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
SophosMal/Generic-S
BaiduWin32.Trojan.Urelas.d
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebTrojan.Siggen6.36651
TrendMicroTROJ_GEN.R002C0DK523
EmsisoftGen:Variant.Zusy.467824 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=87)
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
VaristW32/Wecod.R.gen!Eldorado
Antiy-AVLTrojan/Win32.Sabsik
Kingsoftmalware.kb.a.993
MicrosoftTrojan:Win32/Urelas.EC!MTB
XcitiumTrojWare.Win32.Small.NAF@531prv
ArcabitTrojan.Zusy.D72370
GDataWin32.Trojan.PSE.1JQAYT4
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4086501
ALYacGen:Variant.Zusy.467824
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DK523
TencentTrojan.Win32.CardSpy.16000130
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CardSpy.PRKJ!tr
AVGWin32:Malware-gen
Cybereasonmalicious.ea729c
AvastWin32:Malware-gen

How to remove Trojan:Win32/Urelas.EC!MTB?

Trojan:Win32/Urelas.EC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment