Trojan

Trojan:Win32/Urelas!pz (file analysis)

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: 84E77E77A4C882AED748.mlw
path: /opt/CAPEv2/storage/binaries/ca6d3d2ac38fcfe89d00517536ff299e005a92da6b4c7c16468acbb00437e90a
crc32: 3ED17D0D
md5: 84e77e77a4c882aed748b358cf9ea9eb
sha1: 2c6f14f57effc7accc42cd33424d9db3bf520cb6
sha256: ca6d3d2ac38fcfe89d00517536ff299e005a92da6b4c7c16468acbb00437e90a
sha512: 0f69b4cab60afa74d02cb3818f2b6b3523c562e57dd47a4582d26822a1086e4a0122c6144a3cbbdf067c98fc4b9788f3f735e062bb5de8215cc9ef71769e514f
ssdeep: 6144:l350dW/XpRpRbcORE3RTVBLG+sHIx9CztHp1ro:lrpxcOK3RTVBYHIxs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138643A117680C071E36617724D16E6B01BADBC3859A4EB4FF7B87E395E301A38A2725F
sha3_384: 27458b0b0433674d87658b9d7d20ad03aef9089ec3f8215aa5bc0b2c5c28b45388fc0c829eec9c78fc4d5c06be208a70
ep_bytes: 00ff7604e8875cffff8b450883c42489
timestamp: 2014-01-11 08:23:43

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lVFy
MicroWorld-eScanGen:Variant.Zusy.303983
ClamAVWin.Malware.Urelas-6717394-0
CAT-QuickHealTrojan.Bulta.B3
SkyhighBehavesLike.Win32.Generic.fm
ALYacGen:Variant.Zusy.303983
Cylanceunsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Urelas.d071f041
Cybereasonmalicious.57effc
ArcabitTrojan.Zusy.D4A36F
BitDefenderThetaGen:NN.ZexaF.36680.smY@a8YoSFi
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.303983
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Urelas.16000161
EmsisoftGen:Variant.Zusy.303983 (B)
BaiduWin32.Trojan.Urelas.a
VIPREGen:Variant.Zusy.303983
TrendMicroTROJ_GEN.R03BC0DAD24
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GoogleDetected
Antiy-AVLTrojan[Downloader]/Win32.Urelas.ab
Kingsoftmalware.kb.a.998
XcitiumTrojWare.Win32.Urelas.AB@56lb34
MicrosoftTrojan:Win32/Urelas!pz
GDataGen:Variant.Zusy.303983
VaristW32/Urelas.DD.gen!Eldorado
AhnLab-V3Trojan/Win.Agent.C5457171
Acronissuspicious
McAfeeGenericRXWA-JV!84E77E77A4C8
MalwarebytesUrelas.Trojan.Downloader.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DAD24
RisingTrojan.Urelas!1.BE13 (CLASSIC)
IkarusTrojan.Win32.Beaugrit
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.49CA!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment