Trojan

What is “Trojan:Win32/Urelas!pz”?

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: C0189FB8A47BAD71DFC2.mlw
path: /opt/CAPEv2/storage/binaries/51ae101c9bc323faa8e1a36beb9ddfb8e718a58566d71f7bda4837ad8a0f3a18
crc32: 8DB71D71
md5: c0189fb8a47bad71dfc286de26153c14
sha1: d50c2a98d342ff9dfdadb12077612c2bae136ab1
sha256: 51ae101c9bc323faa8e1a36beb9ddfb8e718a58566d71f7bda4837ad8a0f3a18
sha512: 480cf0589e92a3736afda8c5d2bda873fd19806f164b09b343e16b788414c294e38a137153354ca266152e3b9e0a0de840798a901fe42f3462bb664474755a8f
ssdeep: 12288:PO1YRlP8/9BG8j6axiEmvTnabAh0ZnAr1U:POt9Q8j9UEkTn4AC1+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182B4AF217240C034F3AA13754952E5B45BA97D355AB4E68FFAA87E791F301C3AA3720F
sha3_384: 063ef137dc0dc7be78b8904954e5ff8e9cac907f2eddf2af6a33262f1b095c8f3ab0440397fb1c3f2fdd0f2050d3832a
ep_bytes: 01f7d983ef018a450cfdf2ae83c70138
timestamp: 2013-11-08 01:45:29

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.440576
CAT-QuickHealTrojan.Bulta.B3
SkyhighBehavesLike.Win32.Generic.gh
McAfeeGenericRXVT-EZ!C0189FB8A47B
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.440576
SangforWorm.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Zusy.440576
BitDefenderThetaGen:NN.ZexaF.36792.FmZ@aCUzsYc
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Malware.Urelas-9978537-0
RisingTrojan.Generic@AI.100 (RDML:HV1WmskID0d/GMjEJcxtkQ)
TACHYONTrojan/W32.Agent.507904.TV
SophosGeneric ML PUA (PUA)
BaiduWin32.Trojan.Urelas.a
F-SecureTrojan.TR/Urelas.tqqaj
FireEyeGeneric.mg.c0189fb8a47bad71
EmsisoftGen:Variant.Zusy.440576 (B)
IkarusTrojan.Win32.Urelas
AviraTR/Urelas.tqqaj
VaristW32/Zusy.QB.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Urelas.ab
Kingsoftmalware.kb.a.996
MicrosoftTrojan:Win32/Urelas!pz
XcitiumTrojWare.Win32.Urelas.ET@5ihp6w
ArcabitTrojan.Zusy.D6B900
GDataGen:Variant.Zusy.440576
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Urelas.R87160
Acronissuspicious
ALYacGen:Variant.Zusy.440576
MAXmalware (ai score=88)
DeepInstinctMALICIOUS
Cylanceunsafe
TencentTrojan.Win32.Urelas.16000132
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NGS!tr
AVGWin32:Dropper-NGS [Drp]
Cybereasonmalicious.8d342f
AvastWin32:Dropper-NGS [Drp]

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment