Malware

Win32/Urelas.AD (file analysis)

Malware Removal

The Win32/Urelas.AD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Urelas.AD virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Anomalous binary characteristics

How to determine Win32/Urelas.AD?


File Info:

crc32: 8A818C7A
md5: 916dfd32fe13729a9c44680cb43eb796
name: 916DFD32FE13729A9C44680CB43EB796.mlw
sha1: 6920e8688f42b9a0a1e363feec23b879038c13b0
sha256: 5f3880d2453de52607aec34d2fddd25bbf7439beb45086ce2eefb6fd56d3aeeb
sha512: c45c76227d898374e163a773a23cd796090a095c3b0fce48281f756fc1c89b4edafb1ea390a76b04b47101b9bd3ae30f44fcefc2127cab95fc946f191980a465
ssdeep: 1536:/XWz7kuLESB3qpMlMRpJglQTK2FILihD2wGe39dPYoCo5nGp3:/X+VLE23SMmtlILmFf55nGp3
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Win32/Urelas.AD also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00493c1e1 )
LionicTrojan.Win32.Generic.m!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader9.39023
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaMalware:Win32/Dorpal.ali1000029
K7GWTrojan ( 00493c1e1 )
Cybereasonmalicious.2fe137
BaiduWin32.Trojan.Urelas.b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Urelas.AD
APEXMalicious
AvastWin32:GenMaliciousA-LJU [Trj]
ClamAVWin.Malware.Urelas-6717394-0
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Heur.Mint.SP.Urelas.1
NANO-AntivirusTrojan.Win32.Urelas.cxqhja
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
TencentMalware.Win32.Gencirc.10b3f1a8
Ad-AwareGen:Heur.Mint.SP.Urelas.1
SophosMal/Generic-S
ComodoTrojWare.Win32.Urelas.SH@5674sp
BitDefenderThetaGen:NN.ZexaF.34266.mmX@amuvHKii
VIPRETrojan.Win32.Urelas.b (v)
McAfee-GW-EditionBehavesLike.Win32.Corrupt.dt
FireEyeGeneric.mg.916dfd32fe13729a
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Generic.aakb
AviraTR/Urelas.smpwq
Antiy-AVLTrojan/Generic.ASMalwS.835EC3
MicrosoftTrojan:Win32/Occamy.C
GDataWin32.Trojan.PSE.1EZZ25Y
AhnLab-V3Malware/RL.Generic.R254510
Acronissuspicious
McAfeePWS-FBQQ!916DFD32FE13
MAXmalware (ai score=100)
VBA32BScope.Trojan.AVKill
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:zMUPu+Su0ekpnAAWiml5/A)
YandexTrojan.Urelas!eV8kr3KzJJQ
IkarusTrojan.Win32.Urelas
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.49CA!tr
AVGWin32:GenMaliciousA-LJU [Trj]
Paloaltogeneric.ml

How to remove Win32/Urelas.AD?

Win32/Urelas.AD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment