Trojan

Should I remove “Trojan:Win32/Urelas!pz”?

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: 4EA2656389A3B8119C6D.mlw
path: /opt/CAPEv2/storage/binaries/5cb257e47d163a6731965b56df640f60c6424a59dca6f4aba1fe024b3afae493
crc32: CDD58FD8
md5: 4ea2656389a3b8119c6d3c243eca133b
sha1: 887dd6f3f27d913dcd480ce5c19fa57fc3ba67c1
sha256: 5cb257e47d163a6731965b56df640f60c6424a59dca6f4aba1fe024b3afae493
sha512: 08c271c53517fed23dad34d63401a64112f2fd4c01c7313bb42fdc3da768ec0f61f0866c3bdc6ac1637d3db73c085526a9fc0d0e9e9ec50dd9831f621f211e3c
ssdeep: 768:P73EWAzAdl4Wxn9Tqfj/qhxZPWBBUC+cYuq0UwwbchsR2KRtQbB/8qi34R2/QASd:P7LvuaeB6C+A/9wbcHKRtQb52dy2A1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171241240BC4A5ADED285817E262FCFEFB1730C2B52B272410BC1365C599CF1EE54A678
sha3_384: 64963f617e051e4998233294f5556c0118b79fd6ac1675bfae84aee1a0911c537e793d5032f1e3b77a979ce9eabe81f3
ep_bytes: 00000000000000000000000000000000
timestamp: 2013-08-07 05:36:17

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Urelas.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.4ea2656389a3b811
SkyhighBehavesLike.Win32.Generic.dz
McAfeeGenericRXAA-FA!4EA2656389A3
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Urelas.Vmdn
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_70% (W)
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
APEXMalicious
AlibabaTrojan:Win32/Urelas.fdf1a9ba
ViRobotTrojan.Win.Z.Urelas.228519
RisingTrojan.Generic@AI.100 (RDML:lV1UXuMYrM8VjB7KUmylOA)
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
Antiy-AVLTrojan/Win32.Wecod
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Urelas!pz
SUPERAntiSpywareTrojan.Agent/Gen-Urelas
GDataWin32.Trojan.PSE.8PVIRE
VaristW32/Urelas.EB.gen!Eldorado
AhnLab-V3Trojan/Win32.Urelas.R79715
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H01K723
SentinelOneStatic AI – Malicious PE
FortinetW32/Urelas.EB!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.3f27d9
AvastWin32:Evo-gen [Trj]

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment