Trojan

Should I remove “Trojan:Win32/Urelas!pz”?

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: 27DDD5A58A78CE3329E5.mlw
path: /opt/CAPEv2/storage/binaries/cb5ad32961d5923b1911ce3d240d4271bf30f75c5ce0c59152d6e5f2d5f1c3c4
crc32: E7DA36C7
md5: 27ddd5a58a78ce3329e5759a924304e6
sha1: 7650a49421784f7a4e3c67dbc226ded2923cf895
sha256: cb5ad32961d5923b1911ce3d240d4271bf30f75c5ce0c59152d6e5f2d5f1c3c4
sha512: ef2204db17e2a0ddeae321de170fee356162302621b90a9f565b90ab29c107245eeaf1cc36c6bff44fcab8eacfa457e4d17a1f8a1c6863f413bdac1035110eba
ssdeep: 3072:N7M5wFxHQ/SXvBouCydnq3sYsvP3vkzmF2TpTzrBw5XqQgqMOiF0Z48GK:y5SXvBoDWKcvkzmSBrBw/gqrMA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124949D6626008826F3190B7A454AF9E04D646D3E18D5F58FEB38BC756D32193DB3B28F
sha3_384: 98820de612cf26f1959a8889418a947d04fe9401619585f8cc196c05c4b9a46b991228b7dd0bbc00f1095002b20e5fe7
ep_bytes: e8ab6f0000e979feffff8bff558bec81
timestamp: 2013-08-07 06:38:42

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mikey.104578
FireEyeGeneric.mg.27ddd5a58a78ce33
SkyhighBehavesLike.Win32.Corrupt.gz
McAfeeGenericRXAA-AA!27DDD5A58A78
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.GenericML.Win32.42797
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.421784
ArcabitTrojan.Mikey.D19882
BitDefenderThetaGen:NN.ZexaF.36680.AuZ@aa3lqLaG
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderGen:Variant.Mikey.104578
AvastWin32:BackdoorX-gen [Trj]
EmsisoftGen:Variant.Mikey.104578 (B)
DrWebTrojan.AVKill.32766
VIPREGen:Variant.Mikey.104578
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Plite.ud
Webroot
GoogleDetected
Antiy-AVLTrojan[Backdoor]/Win32.Plite
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Urelas!pz
ZoneAlarmUDS:Trojan.Win32.GenericML.xnet
GDataWin32.Trojan.PSE.10FJZGG
CynetMalicious (score: 100)
MAXmalware (ai score=84)
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:XeZUcn+XFdhvobBR7tmgjw)
IkarusTrojan.Win32.Urelas
MaxSecureTrojan.Malware.121218.susgen
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment