Trojan

About “Trojan:Win32/Urelas!pz” infection

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: 3F7394D09B8A3211FB98.mlw
path: /opt/CAPEv2/storage/binaries/6fe3ecc8f154b957b106615f7c5e095c905c35ad8e2aba51d63bde8f435aefbc
crc32: 525A6FB2
md5: 3f7394d09b8a3211fb989bd37383b901
sha1: 03c878ee0d536c2b5238a3c452784a02a332dc2a
sha256: 6fe3ecc8f154b957b106615f7c5e095c905c35ad8e2aba51d63bde8f435aefbc
sha512: 7465a4e8bd308169304e6c8ecae009f40b066ac2165c285e14b6bcfc79441ec78911413cbc7eee91b28d707e339a8e27374429ee9a6d74e2e9a6f19ac27d5405
ssdeep: 1536:G9BLws2AenpKkoc842ftwXUJCOkLrCwf3/o3RQZs56m3x0HnPx/YM655vwYFBR:G9KHnp2ChLGIPo+YM65ZwwR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB0418103640C432E75907304916EBE1497D6CB919E9E98FF7A87E3A5E322C3D67B24E
sha3_384: deed58817a1bc5725edab35d2f8ffad07f653796a88d7bb99a45d3898b3c53963110fa0047813d9db898dbf22a3f2d3d
ep_bytes: 83ec1853565733db6a015353ff750889
timestamp: 2014-06-10 15:03:58

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.531525
SkyhighBehavesLike.Win32.Generic.ct
McAfeeGenericRXAA-AA!3F7394D09B8A
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Zusy.D81C45
BitDefenderThetaGen:NN.ZexaF.36680.kyZ@aSdtL7
VirITWin95.Marburg
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Urelas-6717394-0
BitDefenderGen:Variant.Zusy.531525
SUPERAntiSpywareTrojan.Agent/Gen-Urelas
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Urelas.16000161
EmsisoftGen:Variant.Zusy.531525 (B)
BaiduWin32.Trojan.Urelas.b
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Zusy.531525
TrendMicroTROJ_GEN.R03BC0DAL24
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Urelas
VaristW32/Urelas.DK.gen!Eldorado
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan[Downloader]/Win32.Urelas.ab
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Urelas!pz
GDataGen:Variant.Zusy.531525
GoogleDetected
ALYacGen:Variant.Zusy.531525
TACHYONTrojan/W32.Agent.176128.CAE
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallTROJ_GEN.R03BC0DAL24
RisingTrojan.Urelas!1.BE13 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.49CA!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.e0d536
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment