Threat Database Trojans Trojan.Urelas.D

Trojan.Urelas.D

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 7,890
Threat Level: 80 % (High)
Infected Computers: 8,568
First Seen: November 16, 2018
Last Seen: July 13, 2026
OS(es) Affected: Windows

The detection of Trojan.Urelas.D on your system indicates a potential security threat that requires immediate attention. This malware is categorized as a Trojan, which is a type of malicious software designed to gain unauthorized access to a computer system. Trojans can be used to steal sensitive information, install additional malware, or provide a backdoor for remote access to the infected system.

What Is Trojan.Urelas.D?

Trojan.Urelas.D is a type of malware that can compromise the security and integrity of your computer system. The name "Trojan" refers to the fact that this type of malware often disguises itself as legitimate software, allowing it to bypass security measures and infect a system. Once inside, it can perform a variety of malicious activities, depending on its design and purpose.

How Trojan.Urelas.D Operates

Trojan.Urelas.D, like other Trojans, operates by exploiting vulnerabilities in software or tricking users into installing it. It may spread through various means, including email attachments, infected software downloads, or compromised websites. Once installed, it can communicate with its command and control servers to receive instructions, which might include stealing data, downloading additional malware, or using the infected computer for malicious activities such as spamming or DDoS attacks.

Symptoms of Infection

Symptoms of a Trojan.Urelas.D infection can vary widely, depending on its intended purpose. Common signs include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You might also notice changes to your browser settings, unexpected pop-ups, or antivirus software being disabled. In some cases, the infection might not display any noticeable symptoms, making it difficult to detect without proper scanning tools.

How to Remove Trojan.Urelas.D

  1. Enter Safe Mode with Networking to prevent the malware from loading and to allow for a clean environment to perform removal steps.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the Trojan and any other malware that might be present.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are sure are malicious or unnecessary.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any changes made by the malware, such as altered homepage settings or malicious extensions.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that the system is clean.

Conclusion

Removing Trojan.Urelas.D requires careful and thorough steps to ensure that all components of the malware are eliminated from your system. It's crucial to use reputable security software and follow best practices for system security to prevent future infections. Regularly updating your operating system, applications, and security software can help protect against known vulnerabilities. Additionally, being cautious with email attachments, downloads, and links can significantly reduce the risk of malware infections. If you're unsure about any part of the removal process, consider seeking help from a professional to ensure your system is fully cleaned and secured.

Analysis Report

General information

Family Name: Trojan.Urelas.D
Packers: UPX!
Signature status: Modified signature

Known Samples

MD5: a04e0ad1304cc6f1703be17cf604acb2
SHA1: 33da3089f937881c1eea99ead4118e1aeea329df
SHA256: FBF1C660283890FB45F5590C3647288AB1AD8B8970D0EB6E7247126C9206D293
File Size: 414.96 KB, 414960 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name WildTangent, Inc.
File Description WTDownloader
File Version 1.0.1.327
Legal Copyright WildTangent, Inc. All rights reserved.
Product Version 1.0.1.327

File Traits

  • 2+ executable sections
  • HighEntropy
  • packed
  • upx
  • UPX!
  • x86

Block Information

Total Blocks: 2,803
Potentially Malicious Blocks: 13
Whitelisted Blocks: 2,282
Unknown Blocks: 508

Visual Map

0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 1 ? ? ? ? ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 1 ? ? 1 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? 0 ? 0 ? ? 0 0 ? 1 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 1 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 1 0 0 0 ? 0 ? ? ? ? 0 ? ? ? 0 1 ? ? 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 ? 1 ? ? ? ? 0 ? 0 0 0 ? 0 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? 1 ? ? 0 ? 0 1 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 1 0 0 ? ? ? 0 0 0 0 0 0 ? 0 0 0 x 0 ? 1 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? 1 ? ? ? 0 ? ? ? 0 ? 0 0 0 ? ? ? 0 ? 0 0 0 ? 0 0 0 ? 0 ? ? 1 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 1 ? ? ? ? ? ? 1 ? ? ? 0 ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 1 0 0 ? ? 0 ? 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 x ? ? x ? ? ? ? 0 ? ? ? ? ? ? x ? ? ? 0 0 ? ? 0 ? 0 0 ? ? 0 ? ? ? x ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 ? ? 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? x 0 ? ? 0 ? ? 0 0 0 0 0 0 1 ? 0 0 0 0 ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 1 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 1 0 0 ? 0 0 0 0 1 0 0 0 0 0 0 0 x 1 x 0 0 x 0 0 0 0 0 1 0 ? ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 ? 1 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 1 0 1 0 0 0 0 0 0 0 0 ? 0 0 0 1 0 0 0 0 0 ? 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 1 ? 0 0 ? 0 0 ? 1 ? ? 0 0 0 0 0 ? ? ? 0 0 1 0 ? 1 ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 1 ? 0 0 0 0 0 1 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 ? 0 1 1 ? 0 0 0 0 0 0 ? 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 ? x 0 0 0 ? 0 0 ? 0 ? ? 0 ? 0 ? 1 ? 1 0 0 0 0 0 0 0 0 1 0 ? 0 0 0 0 1 0 0 ? 0 ? 0 0 ? 0 0 ? ? ? 1 ? 0 ? ? ? ? ? 0 1 0 0 ? 0 0 ? 0 0 0 0 0 ? ? ? ? 0 0 ? 0 ? ? ? 0 0 0 0 ? ? ? ? 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 1 ? 0 ? ? ? 0 ? ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? 0 ? ? ? 0 0 0 0 0 0 ? ? 0 ? ? ? 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 ? ? ? ? 1 0 ? ? 0 0 ? x 0 ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? ? 0 ? ? 0 0 ? 0 ? ? 0 0 ? ? 0 ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? 0 0 0 ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? 0 0 ? 0 ? ? 0 0 ? 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 2 2 0 0 0 1 0 0 0 0 0 0 0 2 0 0 1 1 1 0 1 0 0 0 0 0 0 1 0 0 1 1 0 0 0 0 0 1 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • NtQuerySystemInformation
User Data Access
  • GetComputerNameEx

Trending

Most Viewed

Loading...