Trojan

Trojan:Win32/Urelas!pz malicious file

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: 72C2C0B473071E04003C.mlw
path: /opt/CAPEv2/storage/binaries/d5482be618cc0e7566696f3b13bb98d706a27c86fd040bb124ef71881939c4a0
crc32: 5103CE0F
md5: 72c2c0b473071e04003c7b9f60caf601
sha1: a3c311c0a2c9219e1d1474ff677dd6752f06869f
sha256: d5482be618cc0e7566696f3b13bb98d706a27c86fd040bb124ef71881939c4a0
sha512: 794dd34f642b71042326025848a32043fbe0b89e6da056e050569e7ed327af9738d27cad167a01a1b2ea7d9f844a2827f67dc290e4bbea28507378d4a4f1d1b1
ssdeep: 1536:vlrhjHNLKAFtNA+szed/PhfUCg26oUy1ed1dYJbd1seqkGT0f3oVB/WtcgnT2tco:zjtLKCEze5N/YEbv9/yUcgnT2tcMn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15894AE3634D0C477E43B00364086CB396B76B8725F2A5A877BD946CD9D212A8DB3F386
sha3_384: 67b32d010588901a35075e52c3634d4c09190e51f60b54c935b7cc5c9ef0fc1ffa142c5c4f40fe24230e0c0611db5da2
ep_bytes: e819690000e917feffff558bec81ec28
timestamp: 2013-09-09 07:29:59

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.94555
ClamAVWin.Malware.Urelas-9956786-0
FireEyeGeneric.mg.72c2c0b473071e04
CAT-QuickHealTrojan.Gupboot.G.mue
SkyhighBehavesLike.Win32.Corrupt.gz
ALYacTrojan.GenericKDZ.94555
Cylanceunsafe
ZillyaBackdoor.Plite.Win32.1095
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:Win32/Urelas.1087
K7GWTrojan ( 0047e3691 )
K7AntiVirusBackdoor ( 0053e8561 )
BitDefenderThetaGen:NN.ZexaF.36744.zmY@aiGE5gc
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Urelas.S
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Plite.bhuz
BitDefenderTrojan.GenericKDZ.94555
NANO-AntivirusTrojan.Win32.Plite.eizuzf
SUPERAntiSpywareTrojan.Agent/Gen-Urelas
AvastWin32:BackdoorX-gen [Trj]
TencentTrojan.Win32.Urelas.16000132
EmsisoftTrojan.GenericKDZ.94555 (B)
BaiduWin32.Trojan.Urelas.a
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.AVKill.33021
VIPRETrojan.GenericKDZ.94555
TrendMicroTrojan.Win32.Urelas.SM
Trapminemalicious.high.ml.score
SophosTroj/Urelas-Q
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.13WEWUT
JiangminBackdoor.Generic.aafa
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Plite
KingsoftWin32.Hack.Plite.bhuz
XcitiumTrojWare.Win32.Urelas.C@51vf2d
ArcabitTrojan.Generic.D1715B
ZoneAlarmBackdoor.Win32.Plite.bhuz
MicrosoftTrojan:Win32/Urelas!pz
VaristW32/Urelas.BB.gen!Eldorado
AhnLab-V3Backdoor/Win.Plite.R459948
McAfeeCorrupt-FY!72C2C0B47307
MAXmalware (ai score=84)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.Urelas.SM
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
YandexTrojan.Urelas!bMmUXypvXHM
IkarusTrojan.Win32.Urelas
MaxSecureBackdoor.Plite.buhz
FortinetW32/Urelas.O!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.0a2c92
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment