Trojan

What is “Trojan:Win32/Urelas.EC!MTB”?

Malware Removal

The Trojan:Win32/Urelas.EC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas.EC!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas.EC!MTB?


File Info:

name: A667FF1C6419B8BDA1AE.mlw
path: /opt/CAPEv2/storage/binaries/2979b8024b351857b0743374b708218d95a5f94a60177508b685984de82e07dd
crc32: E4F5F3E3
md5: a667ff1c6419b8bda1ae7f0ab2a23f9a
sha1: fb43176a7a23ff44372bdd7e63dc81d0ff01f9e0
sha256: 2979b8024b351857b0743374b708218d95a5f94a60177508b685984de82e07dd
sha512: d754f00bc6cdc083b0874b4970033d5e41538fbc5cb2fd8c2bcd3d980d5b8244e4641cff6336cb1e3540e7d96efb5ee6fd0140b77d68b16c437053e8c769b7d9
ssdeep: 6144:S6XJlF85y/ltdkBMLzacdDVxpgQISzqJRyR:n5TQcljkBMKcEc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CDD47B10768080B2E3690770051AF6F54A69AE3917A9A5CFF3783E765E312D35B3728F
sha3_384: 8c3e88d7f5d04770632774f67e44418608e043ee7937972b206e55e3ca9de42fc03f85917619cb73c817ff0fbad1b77a
ep_bytes: 00000000000000000000000000000000
timestamp: 2013-08-26 07:12:45

Version Info:

0: [No Data]

Trojan:Win32/Urelas.EC!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.98586
CAT-QuickHealTrojan.Urelas
SkyhighBehavesLike.Win32.Generic.jt
Cylanceunsafe
VIPRETrojan.GenericKDZ.98586
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D1811A
BaiduWin32.Trojan.Urelas.d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.GKRR
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Mikey-9891201-0
KasperskyTrojan.Win32.Wecod.jdnc
BitDefenderTrojan.GenericKDZ.98586
AvastWin32:Malware-gen
TencentTrojan.Win32.CardSpy.16000130
EmsisoftTrojan.GenericKDZ.98586 (B)
DrWebTrojan.Siggen6.36651
ZillyaTrojan.Wecod.Win32.14127
TrendMicroTROJ_GEN.R03BC0DAF24
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Urelas
Antiy-AVLTrojan/Win32.GenKryptik
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Urelas.AB@56lb34
MicrosoftTrojan:Win32/Urelas.EC!MTB
ZoneAlarmTrojan.Win32.Wecod.jdnc
GDataWin32.Trojan.PSE.102K66A
VaristW32/Urelas.DN.gen!Eldorado
AhnLab-V3Trojan/Win.Urelas.R567676
Acronissuspicious
ALYacTrojan.GenericKDZ.98586
MalwarebytesGeneric.Malware.AI.DDS
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallTROJ_GEN.R03BC0DAF24
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Mabezat.Dam
FortinetW32/CardSpy.PRKJ!tr
AVGWin32:Malware-gen
Cybereasonmalicious.a7a23f
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Urelas.EC!MTB?

Trojan:Win32/Urelas.EC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment