Malware

Win32/Urelas.X removal guide

Malware Removal

The Win32/Urelas.X is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Urelas.X virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Created a process from a suspicious location

How to determine Win32/Urelas.X?


File Info:

name: 4A84168E18E9E6F2169F.mlw
path: /opt/CAPEv2/storage/binaries/b8405beccb329833f027e72e8f3b3e0e6b238368fc0e73f13e57c230afdacf90
crc32: D30592AF
md5: 4a84168e18e9e6f2169f4136e51fb063
sha1: fe33f18ce4f2c8ba07aab4ce2f1372bb99bad0be
sha256: b8405beccb329833f027e72e8f3b3e0e6b238368fc0e73f13e57c230afdacf90
sha512: ac842e5864d3c643f100fff6f84c8b7548917dccce5059f67fffaa63a9adedc6a86aeb6c58c867c3cf1200ff8ba0634b88e98c1bae36a9eef67ad962b3c09b31
ssdeep: 12288:Al+ZmuQEpbjNpTa9nzuRbBUHUpRAwHPf4us8v1TCo31rvMO8qgsgVIoSUhibNqzm:5jpUqBUKQubvx3FvM5qehib+f3NBmnbd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ECF4234182859898F30C1B74592AF5C01AB08DBC58E5F54FF63CBD3A2972A975A3738F
sha3_384: d7d88a61d517d8798cd9f90ac64788838cf7fc73a434b7fc762ab4133d5bb9f5be0be79d4bed31c671eb12df153bd696
ep_bytes: 60be004055008dbe00d0eaff5789e58d
timestamp: 2013-11-13 09:49:48

Version Info:

0: [No Data]

Win32/Urelas.X also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.4a84168e18e9e6f2
CAT-QuickHealTrojan.Gupboot.G.mue
CylanceUnsafe
VIPRETrojan.Win32.Urelas.o (v)
K7AntiVirusBackdoor ( 0053e8561 )
K7GWBackdoor ( 0053e8561 )
Cybereasonmalicious.e18e9e
BaiduWin32.Trojan.Urelas.a
VirITBackdoor.Win32.Generic.CIZE
CyrenW32/A-fc5eff80!Eldorado
ESET-NOD32a variant of Win32/Urelas.X
APEXMalicious
ClamAVWin.Trojan.Agent-1112144
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.SP.Urelas.1
NANO-AntivirusTrojan.Win32.cnfmpe.eaqejb
SUPERAntiSpywareTrojan.Agent/Gen-CardSpy
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
AvastWin32:Dropper-NLU [Drp]
TencentTrojan.Win32.Urelas.16000132
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
ComodoTrojWare.Win32.Urelas.U@54nwdv
DrWebTrojan.StartPage.57307
ZillyaBackdoor.Plite.Win32.125
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.bc
SophosML/PE-A + Troj/Urelas-AA
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bapdd
AviraBDS/Backdoor.Gen7
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.62ABA1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.Agent.784082
GDataGen:Heur.Mint.SP.Urelas.1
AhnLab-V3Backdoor/Win32.Plite.R94928
McAfeeGenericRXAA-AA!4A84168E18E9
VBA32SScope.Backdoor.Urelas.3114
MalwarebytesMalware.AI.4259907050
RisingTrojan.Urelas!8.1F5 (RDMK:cmRtazoke3tRfiqas5WAIsmebhmO)
FortinetW32/Generic.AC.20DE!tr
BitDefenderThetaGen:NN.ZexaF.34182.VmXaai!sV3fO
AVGWin32:Dropper-NLU [Drp]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/Urelas.X?

Win32/Urelas.X removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment