Malware

Win32/Urelas.D removal guide

Malware Removal

The Win32/Urelas.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Urelas.D virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Urelas.D?


File Info:

name: CEC315C990D8A4ADD09B.mlw
path: /opt/CAPEv2/storage/binaries/8516fdec25a5606c095b79a2f2e51d9cfa659de5cbd41016f260afc908426921
crc32: 39351399
md5: cec315c990d8a4add09bac450ac6d4fc
sha1: a1cde12ca1d189d1a5c9d09ddcb06e20428e0d8c
sha256: 8516fdec25a5606c095b79a2f2e51d9cfa659de5cbd41016f260afc908426921
sha512: 9a6284e2408252b3f078afdbf5d825a4c263a41d4997191b418ecfed7af0c7ab622b84e1ffaf7135ab4f03759c60a41a2f1554eebdf5234dcfbf3b0a49b1ba15
ssdeep: 6144:MLQvSxKp2HLZ4JOvzTvzj/PPjTD/zDjDDTzTz/Pf//DzDzvj:MWSxK0H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE158D117BE0D073C46A543040A9D7735A7EB9361A75C583BBA52B3E5E312C2EA3B34E
sha3_384: ddc8455e0c18d7e479a82f7a5ed7a63a11acb22f379baa6578b73017c5b025bce456afabcef9da7bd602306b5eecccef
ep_bytes: e8eb640000e979feffff8bff558bec81
timestamp: 2012-10-02 05:56:36

Version Info:

CompanyName: Microsoft Corperation
FileDescription: Generic Host Process for Win32 Services
FileVersion: 1, 0, 0, 48
InternalName: procexp.exe
LegalCopyright: Copyright (c) Microsoft. All rights reserved.
OriginalFilename: procexp.exe
ProductName: Microsoft Windows Operating System
ProductVersion: 1, 0, 0, 48
Translation: 0x0412 0x04b0

Win32/Urelas.D also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.64106142
ClamAVWin.Malware.Urelas-9980267-0
FireEyeGeneric.mg.cec315c990d8a4ad
CAT-QuickHealTrojan.Swisyn.16719
McAfeeGeneric Malware.mt
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Swisyn.Win32.27758
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003eb0af1 )
K7GWTrojan ( 003eb0af1 )
Cybereasonmalicious.ca1d18
CyrenW32/Urelas.CW.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Urelas.D
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Swisyn.fokq
BitDefenderTrojan.GenericKD.64106142
NANO-AntivirusTrojan.Win32.FKM.bbxcik
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10bdae9e
EmsisoftTrojan.GenericKD.64106142 (B)
F-SecureTrojan.TR/Crypt.FKM.Gen
DrWebTrojan.DownLoader6.64322
VIPRETrojan.GenericKD.64106142
McAfee-GW-EditionBehavesLike.Win32.Fake.dz
Trapminemalicious.high.ml.score
SophosMal/Urelas-A
IkarusTrojan.Win32.Gupboot
JiangminTrojan/Swisyn.uvu
WebrootW32.Trojan.Gen
AviraTR/Crypt.FKM.Gen
Antiy-AVLTrojan/Win32.Swisyn
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Generic.D3D22E9E
ZoneAlarmTrojan.Win32.Swisyn.fokq
GDataTrojan.GenericKD.64106142
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5321839
Acronissuspicious
VBA32BScope.Trojan.Swisyn
ALYacTrojan.GenericKD.64106142
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Urelas!8.1F5 (TFE:5:qrpjF6M15mK)
YandexTrojan.GenAsa!7uOruBFrSwE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Urelas.GG!tr
BitDefenderThetaGen:NN.ZexaF.36738.5u3@a0byrCiO
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Urelas.D?

Win32/Urelas.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment