Trojan

Trojan:Win32/Urelas!pz malicious file

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: 7592C10FB8C6B6743F67.mlw
path: /opt/CAPEv2/storage/binaries/6a50d53c605c55925753674117088d075c69ffb9365b4518aa7afdf26500b3ab
crc32: FB06F872
md5: 7592c10fb8c6b6743f678b83d028403b
sha1: 003ba939e657a4e2ed6d29566546d8cacc6cd13e
sha256: 6a50d53c605c55925753674117088d075c69ffb9365b4518aa7afdf26500b3ab
sha512: d30f4828f501a341ab88680f55ce0fc6cbd0937ac68bbe6257d4ad5a806d405a0f5ec978094b73ca295ba1033ed48609ac25d8a18e62f48721cc9bfdd4f3cd28
ssdeep: 1536:FfXMLiOHYcU966RFholE8EjiC2dXuLo0fsuP2GcJMttlPI7sWjcd0v650NHMe7:9c2jyketdXpW2NMrlPIEM65cse7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166F36B0076D18071D0764534066983A26B7D7D729BA98E9FB7841E7D8AB42C0BB33BB7
sha3_384: 9a05d1f864bb1490da9dc09868c5f4ec6882d0ce40236f172f5f5f087abaac1f3f47dc776fd3cfe51b730347e3b57bc0
ep_bytes: e8d41e0000ff7508e813220000833d3c
timestamp: 2014-10-14 09:22:49

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.452027
SkyhighBehavesLike.Win32.Generic.ct
MalwarebytesGeneric.Malware.AI.DDS
SangforVirus.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.9e657a
ArcabitTrojan.Zusy.D6E5BB
BaiduWin32.Trojan.Urelas.b
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Urelas-6717394-0
BitDefenderGen:Variant.Zusy.452027
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Urelas.16000161
SophosML/PE-A
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Zusy.452027
TrendMicroTROJ_GEN.R03BC0DAL24
EmsisoftGen:Variant.Zusy.452027 (B)
IkarusTrojan.Patched
VaristW32/Urelas.DK.gen!Eldorado
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan[Downloader]/Win32.Urelas.ab
Kingsoftmalware.kb.a.969
MicrosoftTrojan:Win32/Urelas!pz
GDataGen:Variant.Zusy.452027
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.kCZ@a4LimQc
ALYacGen:Variant.Zusy.452027
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DAL24
RisingTrojan.Urelas!1.BE13 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.49CA!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment