Trojan

Should I remove “Trojan:Win32/Urelas!pz”?

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: 517DCF48FBDCB094EF94.mlw
path: /opt/CAPEv2/storage/binaries/0603fa5aaaded429ef3dbc1ea08adceb4d084159eca9fbf7e7072df93661ad98
crc32: A0EA7F90
md5: 517dcf48fbdcb094ef94bb67aef2c1fe
sha1: d2a4b40752267a405a7e19fd50680281f5327435
sha256: 0603fa5aaaded429ef3dbc1ea08adceb4d084159eca9fbf7e7072df93661ad98
sha512: 5b5b872f3cb16eaea22fb28b27db9bd5d31dd1f75a7a9b99f8d29c22fd4271e426a3552d8bee979c5194ff17bdce605d9592daac86e55c77df8ecf639d315618
ssdeep: 3072:mV/0QWR4cXLiQ27x3Fr6l0F+vuL0zHuIvKuNVBH/goBDmF5lQ7:2/9wb2RFGl0cuL0u8KuNVidQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T129D46C1076908072D3A61B31046AE6B54A7A7E3917A5A1CFF3787A396F302D35B3734E
sha3_384: 685dc038491eb8ec555c3e79ed9a414bc1ae8692584bb98d237d78569932240c93bfca344754e25cfb4b43c3568861ad
ep_bytes: 470383ee01c1e90283ef0183f90872b2
timestamp: 2013-08-27 01:43:42

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Graftor.755697
SkyhighBehavesLike.Win32.Generic.jz
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Graftor.755697
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Graftor.755697
K7GWTrojan ( 005a4eb91 )
K7AntiVirusTrojan ( 005a4eb91 )
BitDefenderThetaGen:NN.ZexaF.36792.NmZ@au9z8Cc
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CMK
APEXMalicious
ClamAVWin.Malware.Wacatac-9770178-0
KasperskyHEUR:Trojan.Win32.Wecod.pef
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
SophosML/PE-A
GoogleDetected
F-SecureTrojan.TR/Crypt.XPACK.Gen2
BaiduWin32.Trojan.Urelas.d
TrendMicroTROJ_GEN.R03BC0DK723
FireEyeGeneric.mg.517dcf48fbdcb094
EmsisoftGen:Variant.Graftor.755697 (B)
IkarusTrojan.Crypt
VaristW32/Wecod.R.gen!Eldorado
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Win32.Emotet
Kingsoftmalware.kb.a.925
MicrosoftTrojan:Win32/Urelas!pz
ArcabitTrojan.Graftor.DB87F1
ZoneAlarmHEUR:Trojan.Win32.Wecod.pef
GDataWin32.Trojan.PSE.102K66A
CynetMalicious (score: 100)
McAfeeGenericRXVS-VG!517DCF48FBDC
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BC0DK723
TencentTrojan.Win32.CardSpy.16000130
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CardSpy.PRKJ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.752267
AvastWin32:Evo-gen [Trj]

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment