Trojan

About “Trojan:Win32/Urelas!pz” infection

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: 3C2FCF5A34EC193CD159.mlw
path: /opt/CAPEv2/storage/binaries/d1480a5d88d86a7f8b7d65de4bbd4b340ed2b5c76af9ce89de9a16418df2d6c3
crc32: A4AE4B1D
md5: 3c2fcf5a34ec193cd15903c351fe105a
sha1: cffd548cf8ecb45d834993582c36b4ddad508a47
sha256: d1480a5d88d86a7f8b7d65de4bbd4b340ed2b5c76af9ce89de9a16418df2d6c3
sha512: ee2849e272be3849c57c15ae5151eb9c6bcf9df65fb44368b71d0da5be18cb1ae0e22b277dcae60fdb24c3a399e74517044d2860df9f3844995bad5381b23708
ssdeep: 3072:pwJg+YlRU7DCnGIqbQs4Kl7H00oLGRvwWfIVZHTgoBB5paQIN3C9ISE0qJiNlUdK:pQgrlGIlstl7roLgw6IVpaQISzqJBN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4D47B20B6808072E36907300967F6E54A6D6E3917A5E5CFF2787E396A312D35B3724F
sha3_384: b692a16c6e2340f100436ede930b3ac699361d9fad2391d55d0e122c8bb4c561807d796040df8c57d44d6f636c36874d
ep_bytes: 470383ee01c1e90283ef0183f90872b2
timestamp: 2013-08-27 01:43:42

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
ElasticWindows.Generic.Threat
DrWebTrojan.Siggen6.36651
MicroWorld-eScanGen:Variant.Graftor.755697
FireEyeGeneric.mg.3c2fcf5a34ec193c
SkyhighBehavesLike.Win32.Generic.jt
McAfeeGenericRXVS-VG!3C2FCF5A34EC
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Wecod.Win32.16507
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a4eb91 )
K7GWTrojan ( 005a4eb91 )
Cybereasonmalicious.cf8ecb
ArcabitTrojan.Graftor.DB87F1
BitDefenderThetaGen:NN.ZexaF.36680.NmZ@a0Yhn9k
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CMK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Wacatac-9770178-0
KasperskyHEUR:Trojan.Win32.Wecod.pef
BitDefenderGen:Variant.Graftor.755697
AvastWin32:Malware-gen
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
SophosML/PE-A
F-SecureTrojan.TR/Crypt.XPACK.Gen2
BaiduWin32.Trojan.Urelas.d
VIPREGen:Variant.Graftor.755697
EmsisoftGen:Variant.Graftor.755697 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/Wecod.R.gen!Eldorado
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Sabsik
XcitiumMalware@#s0739i1p4oty
MicrosoftTrojan:Win32/Urelas!pz
ViRobotTrojan.Win32.LockBit.647168
ZoneAlarmHEUR:Trojan.Win32.Wecod.pef
GDataWin32.Trojan.PSE.102K66A
GoogleDetected
Acronissuspicious
TACHYONTrojan/W32.Wecod.647168.T
Cylanceunsafe
PandaTrj/CI.A
TencentTrojan.Win32.CardSpy.16000130
IkarusTrojan.Win32.Urelas
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CardSpy.PRKJ!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment