Trojan

Trojan:Win32/Urelas!pz information

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: 6EBD75698A9B21F707DE.mlw
path: /opt/CAPEv2/storage/binaries/45f5555b83d6bee93232ea290d127bbdfebba9006e05daad75fe6e367afc2f45
crc32: FF061C1D
md5: 6ebd75698a9b21f707deede07111684f
sha1: 24dfbbb5ccaa112ccba4d2fdd0e7bb7a5d31307e
sha256: 45f5555b83d6bee93232ea290d127bbdfebba9006e05daad75fe6e367afc2f45
sha512: 8c67bcb6e01613bd8b687df5936dc4610fb53ed3f3ce280334e4dfbab4bf0380f27b88af78cf8f7650f0b9b96de21ff8518e158a1ef74ef7c547f4cd9bb91cb3
ssdeep: 1536:vlrhjHNLKAFtNA+szed/PhfUCg26oUy1ed1dYJbd1seqkGT0f3oVB/WtcgnT2tcU:zjtLKCEze5N/YEbv9/yUcgnT2tcU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CE949E3634D0C477D43B00364486CB356A76B8725F2A5A877FD94ACD9E212A8DB3F386
sha3_384: 3b0e72b4938360d08ca63a5f03b4794d6d8a8d1e72156c4614deaa1e99110a0b0fcd18531957e928f192f186d934bb20
ep_bytes: e819690000e917feffff558bec81ec28
timestamp: 2013-09-09 07:29:59

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Plite.tp0w
AVGWin32:BackdoorX-gen [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.33021
MicroWorld-eScanTrojan.GenericKDZ.94555
FireEyeGeneric.mg.6ebd75698a9b21f7
CAT-QuickHealTrojan.Gupboot.G.mue
SkyhighBehavesLike.Win32.Corrupt.gz
McAfeeCorrupt-FY!6EBD75698A9B
Cylanceunsafe
ZillyaBackdoor.Plite.Win32.1095
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 0053e8561 )
AlibabaBackdoor:Win32/Urelas.1087
K7GWTrojan ( 0047e3691 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.zmY@aiGE5gc
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Urelas.S
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Urelas-9956786-0
KasperskyBackdoor.Win32.Plite.bhuz
BitDefenderTrojan.GenericKDZ.94555
NANO-AntivirusTrojan.Win32.Plite.eizuzf
SUPERAntiSpywareTrojan.Agent/Gen-Urelas
AvastWin32:BackdoorX-gen [Trj]
TencentTrojan.Win32.Urelas.16000132
EmsisoftTrojan.GenericKDZ.94555 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
BaiduWin32.Trojan.Urelas.a
VIPRETrojan.GenericKDZ.94555
TrendMicroTrojan.Win32.Urelas.SM
Trapminemalicious.high.ml.score
SophosTroj/Urelas-Q
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Generic.aafa
WebrootW32.Trojan.Gen
VaristW32/Urelas.BB.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Backdoor]/Win32.Plite
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Urelas!pz
XcitiumTrojWare.Win32.Urelas.C@51vf2d
ArcabitTrojan.Generic.D1715B
ZoneAlarmBackdoor.Win32.Plite.bhuz
GDataWin32.Trojan.PSE.13WEWUT
GoogleDetected
AhnLab-V3Backdoor/Win.Plite.R459948
VBA32Trojan.AVKill
ALYacTrojan.GenericKDZ.94555
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.Urelas.SM
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
YandexTrojan.Urelas!bMmUXypvXHM
IkarusTrojan.Win32.Urelas
MaxSecureBackdoor.Plite.buhz
FortinetW32/Urelas.O!tr
Cybereasonmalicious.98a9b2
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Plite.A(dyn)

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment