Trojan

Trojan:Win32/Urelas!pz removal instruction

Malware Removal

The Trojan:Win32/Urelas!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Urelas!pz virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Urelas!pz?


File Info:

name: 1F89D95C4D5116418113.mlw
path: /opt/CAPEv2/storage/binaries/f8c8adac59fd47ab34eb64225d5b24acd1f2c8726f15c95bccb94723e8fba336
crc32: 8668C7D6
md5: 1f89d95c4d511641811385625ac59bd3
sha1: e53edc113843cdd3b92264ca5d624f63e8faded3
sha256: f8c8adac59fd47ab34eb64225d5b24acd1f2c8726f15c95bccb94723e8fba336
sha512: edd12c1290f690dd823f5d29dafce4114ff2413bd39d48dd7e4f2f0ee0064b4d374b3c292f982a8b32e4dcf8cf6c45a74f10457016a6d5b21cad4dba40e173f1
ssdeep: 12288:q2PxDgZo3ijniea5Xih9abyNK95ZA9u3y2XW:q2SLi7Rih9abvce
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F5B4BF113640C076E36627314985E6F529AABC3549A5E60FFBA87F395E301938B3B34F
sha3_384: 5621854a9bf478c0ab41b3c103bb20a4de54c6b88d65a18b28befee9654d1963d49cde6873031c74d34c108dbda71d4c
ep_bytes: 01f7d983ef018a450cfdf2ae83c70138
timestamp: 2013-10-22 07:06:55

Version Info:

0: [No Data]

Trojan:Win32/Urelas!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.33554
MicroWorld-eScanGen:Variant.Fragtor.246090
ClamAVWin.Packed.Urelas-9879149-0
FireEyeGeneric.mg.1f89d95c4d511641
SkyhighBehavesLike.Win32.Generic.hh
McAfeeDownloader-ASH.gen.g
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.GenericML.Win32.8357
SangforWorm.Win32.Save.a
K7AntiVirusTrojan ( 005a20a41 )
K7GWTrojan ( 005a20a41 )
ArcabitTrojan.Fragtor.D3C14A
BitDefenderThetaGen:NN.ZexaF.36608.FuZ@a0!Qmie
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Fragtor.246090
SUPERAntiSpywareTrojan.Agent/Gen-Urelas
AvastWin32:BackdoorX-gen [Trj]
TencentTrojan.Win32.Urelas.16000132
EmsisoftGen:Variant.Fragtor.246090 (B)
BaiduWin32.Trojan.Urelas.a
VIPREGen:Variant.Fragtor.246090
TrendMicroTROJ_GEN.R03BC0DLV23
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=83)
Antiy-AVLTrojan[Downloader]/Win32.Urelas.ab
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.Gupboot.BB@53dg1h
MicrosoftTrojan:Win32/Urelas!pz
ZoneAlarmHEUR:Backdoor.Win32.Generic
GDataWin32.Trojan.PSE.7880KP
VaristW32/Urelas.AP.gen!Eldorado
ALYacGen:Variant.Fragtor.246090
TACHYONBackdoor/W32.Agent.516096.AX
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BC0DLV23
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
YandexTrojan.AVKill!MirXTycLiAI
IkarusTrojan.Win32.Urelas
MaxSecureTrojan.Malware.185628869.susgen
FortinetW32/Agent.NGS!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Urelas!pz?

Trojan:Win32/Urelas!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment