Trojan

Trojan:Win32/Urelas!pz removal instruction

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: D64AA3313B90452D3965.mlw
path: /opt/CAPEv2/storage/binaries/ea44b379024917ae8686db238f22f2ca4ca4e953ce350847433786851f9a54b9
crc32: FE103906
md5: d64aa3313b90452d396564a874e3a52a
sha1: 16e15bec9f168a2d3923af02a972bd6132e4c173
sha256: ea44b379024917ae8686db238f22f2ca4ca4e953ce350847433786851f9a54b9
sha512: a9806575b5e564336bdb365d6db613623ce353d31881b5951af0235a24cb31469373d6e37ae2d390d125b053cc39e153170606ee828d164e06c61bdcd8279b44
ssdeep: 6144:X93MxURBa5LgRGZ1157Lsj3uV/c8ZcOLBDlBRq4:X93Ha5LEm1157uSbCOR/R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175E47C20B6408035E3AA07714A67E5E54A6C6E341395A1CFF2B87E766F713D36A3324F
sha3_384: 1621cf3734153fae732f6c17dfdd9f049280607bee102ff05ef2615a692fd834c2272993972284569f879d9779be6886
ep_bytes: 0fff750c56ff7508e81916000083c40c
timestamp: 2013-08-05 13:52:22

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
CyrenCloudW32/Wecod.R.gen!Eldorado
LionicTrojan.Win32.Wecod.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.296754
FireEyeGeneric.mg.d64aa3313b90452d
SkyhighBehavesLike.Win32.Generic.jt
ALYacGen:Variant.Fugrafa.296754
Cylanceunsafe
ZillyaTrojan.AgentAGen.Win32.68276
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ac9b31 )
AlibabaTrojan:Win32/Wecod.46e5c06c
K7GWTrojan ( 005ac9b31 )
Cybereasonmalicious.c9f168
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CMZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Wecod.jfku
BitDefenderGen:Variant.Fugrafa.296754
AvastWin32:Malware-gen
TencentTrojan.Win32.CardSpy.16000130
Ad-AwareGen:Variant.Fugrafa.296754
EmsisoftGen:Variant.Fugrafa.296754 (B)
BaiduWin32.Trojan.Urelas.d
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebTrojan.Siggen5.60232
VIPREGen:Variant.Fugrafa.296754
TrendMicroTROJ_GEN.R03BC0PKR23
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
VaristW32/Wecod.R.gen!Eldorado
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojan:Win32/Urelas!pz
XcitiumTrojWare.Win32.Wecod.AL@55njeb
ArcabitTrojan.Fugrafa.D48732
ZoneAlarmTrojan.Win32.Wecod.jfku
GDataWin32.Trojan.PSE.102K66A
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Wecod.R340150
Acronissuspicious
McAfeeGenericRXRW-OZ!D64AA3313B90
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R03BC0PKR23
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
IkarusTrojan.Win32.Urelas
FortinetW32/CardSpy.PRKJ!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment