Trojan

Trojan:Win32/Urelas!pz malicious file

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the shellcode get eip malware family
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: D8557177A588D38B84E5.mlw
path: /opt/CAPEv2/storage/binaries/fb0ebdf7252bd7b0a68796f0d8b411104e81f00566f34ab2a743fae79afe4e3b
crc32: 3DC67789
md5: d8557177a588d38b84e590609fea4eff
sha1: 2a329576b265ac3b999134deecccdde58a2b4823
sha256: fb0ebdf7252bd7b0a68796f0d8b411104e81f00566f34ab2a743fae79afe4e3b
sha512: ba2a8f25196e02cf6d0ddd56690f8e9c80e80525984212c4f3068f405f52a5a875a5ae059466f70bd4b272b7306291c572fb29bf2b2a950de6216704ad312c94
ssdeep: 6144:ZajY1oC+/U8Vjlx4kk9HKda4L38NWPzMJiTGiiW13HY2SYtJd:POlx4kk9HKda4YNg13HYY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187B4CF213780C435E3A613714997E2F45A997E345AA4D68FF7A83E795E302C39A3324F
sha3_384: e4809e8c68bef5dff8f8be8dc530d35aac368e13abc4f4853335a4c50b5a2a4558145a323ed614ff810381799be1fb33
ep_bytes: e80ea10000e979feffff8bff558bec51
timestamp: 2013-10-06 02:25:02

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
ElasticWindows.Generic.Threat
MicroWorld-eScanTrojan.GenericKDZ.96204
ClamAVWin.Packed.Mikey-9645700-0
FireEyeGeneric.mg.d8557177a588d38b
CAT-QuickHealTrojan.Gupboot.G.mue
SkyhighBehavesLike.Win32.Corrupt.hh
McAfeeBackDoor-FBLQ!D8557177A588
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Urelas.Win32.38788
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 0053e8561 )
K7GWTrojan ( 0047e3691 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Urelas.a
SymantecInfostealer.Gampass
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Urelas.S
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Plite.bhtj
BitDefenderTrojan.GenericKDZ.96204
NANO-AntivirusTrojan.Win32.cruvjf.eaqdyr
SUPERAntiSpywareTrojan.Agent/Gen-Fragtor
AvastWin32:Dropper-NGS [Drp]
TencentTrojan.Win32.Urelas.16000132
EmsisoftTrojan.GenericKDZ.96204 (B)
F-SecureHeuristic.HEUR/AGEN.1317530
DrWebTrojan.DownLoader10.26373
VIPRETrojan.GenericKDZ.96204
Trapminemalicious.moderate.ml.score
SophosTroj/Urelas-Q
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.38IIUS
JiangminBackdoor.Generic.zqq
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1317530
MAXmalware (ai score=85)
Antiy-AVLTrojan[Backdoor]/Win32.Plite
XcitiumTrojWare.Win32.Urelas.ET@5ihp6w
ArcabitTrojan.Generic.D177CC
ZoneAlarmBackdoor.Win32.Plite.bhtj
MicrosoftTrojan:Win32/Urelas!pz
VaristW32/Urelas.E.gen!Eldorado
AhnLab-V3Trojan/Win.Urelas.R492036
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.FmX@au6LwukO
ALYacTrojan.GenericKDZ.96204
VBA32BScope.Trojan.AVKill
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
YandexTrojan.GenAsa!PtO2O3kjWvs
IkarusTrojan.Win32.Gupboot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Urelas.U!tr
AVGWin32:Dropper-NGS [Drp]
Cybereasonmalicious.6b265a
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment