Trojan

Trojan:Win32/Urelas!pz removal guide

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: 17474530C92D64C31B65.mlw
path: /opt/CAPEv2/storage/binaries/ed827e8491ea07ad2ad2b1f9e60843d7067cf90f61abfb1f474d926cbf205d4f
crc32: 9610EAB2
md5: 17474530c92d64c31b650d6f6e5051f0
sha1: bdc7db8e11c7ce910e0a101393b12675ef892790
sha256: ed827e8491ea07ad2ad2b1f9e60843d7067cf90f61abfb1f474d926cbf205d4f
sha512: c9804e10ee0f6af52d4cf5c3af2491b11aecfa41739b40e68ff358c263adf82c978891b03e24bd3b794178dbacc7c221ede56a56d1c7e98d5c5ef00b339c3e8b
ssdeep: 1536:qvCFWgl0JN82PmUMKr5ZuygLZQMmsc+y303c3I65syOvpxyTf:qvCFWRm5uuFLeMmBnI65RupxW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E614D41066008871F3190B704916FAE449AAAD7D56E8F58FF67C7E3A6D321C39A7324F
sha3_384: 1ee4b9ed922ca28bbe8b44de6650e9ef6828cbb74a27586c7c775aef478adf2090ddaccb09710439f764db67fd76be27
ep_bytes: 081000008b178b84241010000053558b
timestamp: 2014-07-05 10:49:27

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Urelas.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.183968
CAT-QuickHealTrojan.Beaugrit.14262
SkyhighBehavesLike.Win32.Generic.cm
ALYacGen:Variant.Cerbu.183968
Cylanceunsafe
SangforVirus.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Urelas.8e59fd7c
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Cerbu.D2CEA0
BitDefenderThetaGen:NN.ZexaF.36744.myY@aGtoB1f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.MZMMDYG
APEXMalicious
ClamAVWin.Malware.Urelas-6717394-0
BitDefenderGen:Variant.Cerbu.183968
SUPERAntiSpywareTrojan.Agent/Gen-Urelas
AvastWin32:Evo-gen [Trj]
RisingTrojan.Urelas!1.BE13 (CLASSIC)
EmsisoftGen:Variant.Cerbu.183968 (B)
BaiduWin32.Trojan.Urelas.a
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Cerbu.183968
TrendMicroTROJ_GEN.R03BC0DAK24
FireEyeGeneric.mg.17474530c92d64c3
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Patched.Ren.Gen
VaristW32/Urelas.DK.gen!Eldorado
Antiy-AVLTrojan/Win32.Urelas.aa
Kingsoftmalware.kb.a.982
XcitiumTrojWare.Win32.Urelas.ASE@5izxb0
MicrosoftTrojan:Win32/Urelas!pz
GDataWin32.Trojan.PSE.122A5Z1
CynetMalicious (score: 100)
Acronissuspicious
McAfeeTrojan-Urelas!17474530C92D
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DAK24
TencentTrojan.Win32.Urelas.16000161
IkarusTrojan.Win32.Beaugrit
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.49CA!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.e11c7c
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment