Spy

About “Urelas.Spyware.Stealer.DDS” infection

Malware Removal

The Urelas.Spyware.Stealer.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Urelas.Spyware.Stealer.DDS virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Urelas.Spyware.Stealer.DDS?


File Info:

crc32: CC644697
md5: 77946ec281d354d64da385f277ef5142
name: 77946EC281D354D64DA385F277EF5142.mlw
sha1: 1f1ec38393e5e4d4f71e9238eb5598d6f2356088
sha256: f2583d09e509ffefd56ad419ae7d38d1cbf02ddad176af31a37cec3da17980b4
sha512: 710cfe4a958b2501f19de39a3c6ee13716e466f2585aee222fdb965bdc7c2f4997b9cdd39fd5a506d9d0f1616e64f59417f7a22a29bde110c0a9e16b40a1e8e2
ssdeep: 12288:kdBNKTCqqwXCcdgT89+MvA+BisqYpxHtSV:kLjQC+fs0gV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Urelas.Spyware.Stealer.DDS also known as:

BkavW32.AIDetectGBM.malware.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
FireEyeGeneric.mg.77946ec281d354d6
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeDropper-FHZ!77946EC281D3
CylanceUnsafe
VIPRETrojan.Win32.Urelas.o (v)
AegisLabTrojan.Win32.GenericCryptor.lM21
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Heur.Mint.SP.Urelas.1
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.281d35
BaiduWin32.Trojan.Urelas.a
CyrenW32/Urelas.E.gen!Eldorado
SymantecBackdoor.Matsnu.B
APEXMalicious
AvastWin32:Dropper-OAF [Drp]
ClamAVWin.Malware.Urelas-6838238-0
KasperskyTrojan-Ransom.Win32.GenericCryptor.czx
NANO-AntivirusTrojan.Win32.demmsd.eaqemx
RisingRansom.GenericCryptor!8.2E88 (CLOUD)
Ad-AwareGen:Heur.Mint.SP.Urelas.1
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
ComodoTrojWare.Win32.Gupboot.BB@53dg1h
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.AVKill.33464
ZillyaBackdoor.PePatch.Win32.40158
TrendMicroTROJ_URELAS.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosML/PE-A + Troj/Urelas-Q
IkarusTrojan.Win32.Toga
JiangminBackdoor/Plite.ah
MaxSecureBackdoor.Plite.BHST
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan[Ransom]/Win32.GenericCryptor
MicrosoftTrojan:Win32/Urelas.AA
ArcabitTrojan.Mint.SP.Urelas.1
SUPERAntiSpywareTrojan.Agent/Gen-Zusy
ZoneAlarmTrojan-Ransom.Win32.GenericCryptor.czx
GDataGen:Heur.Mint.SP.Urelas.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Urelas.R92523
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.FuX@aOnf!bcO
TACHYONRansom/W32.Agent.518560
VBA32BScope.Trojan.AVKill
MalwarebytesUrelas.Spyware.Stealer.DDS
PandaTrj/Genetic.gen
ZonerTrojan.Win32.31251
ESET-NOD32a variant of Win32/Urelas.U
TrendMicro-HouseCallTROJ_URELAS.SMC
TencentRansom.Win32.CryLock.a
YandexTrojan.Urelas!2wQyqHhm58c
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_92%
FortinetW32/Urelas.O!tr
WebrootW32.Trojan.Gen
AVGWin32:Dropper-OAF [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Urelas.M

How to remove Urelas.Spyware.Stealer.DDS?

Urelas.Spyware.Stealer.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment