Threat Database Trojans Trojan.Urelas.D

Trojan.Urelas.D

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 8,860
Threat Level: 80 % (High)
Infected Computers: 8,572
First Seen: November 16, 2018
Last Seen: August 8, 2026
OS(es) Affected: Windows

The detection of Trojan.Urelas.D on your system indicates a potential security threat that requires immediate attention. This malware is categorized as a Trojan, which is a type of malicious software designed to gain unauthorized access to a computer system. Trojans can be used to steal sensitive information, install additional malware, or provide a backdoor for remote access to the infected system.

What Is Trojan.Urelas.D?

Trojan.Urelas.D is a type of malware that can compromise the security and integrity of your computer system. The name "Trojan" refers to the fact that this type of malware often disguises itself as legitimate software, allowing it to bypass security measures and infect a system. Once inside, it can perform a variety of malicious activities, depending on its design and purpose.

How Trojan.Urelas.D Operates

Trojan.Urelas.D, like other Trojans, operates by exploiting vulnerabilities in software or tricking users into installing it. It may spread through various means, including email attachments, infected software downloads, or compromised websites. Once installed, it can communicate with its command and control servers to receive instructions, which might include stealing data, downloading additional malware, or using the infected computer for malicious activities such as spamming or DDoS attacks.

Symptoms of Infection

Symptoms of a Trojan.Urelas.D infection can vary widely, depending on its intended purpose. Common signs include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You might also notice changes to your browser settings, unexpected pop-ups, or antivirus software being disabled. In some cases, the infection might not display any noticeable symptoms, making it difficult to detect without proper scanning tools.

How to Remove Trojan.Urelas.D

  1. Enter Safe Mode with Networking to prevent the malware from loading and to allow for a clean environment to perform removal steps.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the Trojan and any other malware that might be present.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are sure are malicious or unnecessary.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any changes made by the malware, such as altered homepage settings or malicious extensions.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that the system is clean.

Conclusion

Removing Trojan.Urelas.D requires careful and thorough steps to ensure that all components of the malware are eliminated from your system. It's crucial to use reputable security software and follow best practices for system security to prevent future infections. Regularly updating your operating system, applications, and security software can help protect against known vulnerabilities. Additionally, being cautious with email attachments, downloads, and links can significantly reduce the risk of malware infections. If you're unsure about any part of the removal process, consider seeking help from a professional to ensure your system is fully cleaned and secured.

Analysis Report

General information

Family Name: Trojan.Urelas.D
Signature status: No Signature

Known Samples

MD5: a04e0ad1304cc6f1703be17cf604acb2
SHA1: 33da3089f937881c1eea99ead4118e1aeea329df
SHA256: FBF1C660283890FB45F5590C3647288AB1AD8B8970D0EB6E7247126C9206D293
File Size: 414.96 KB, 414960 bytes
MD5: 9a11242a9196086efc56f18d548d7ffa
SHA1: 05552d73aeb6439ef3db533635eb7b273d22e87d
SHA256: 588DF189D87F6F5DCA3DF912DDBFDD08FE1DD90D4EB9ED449D680906177DAF20
File Size: 141.07 KB, 141074 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Updater
  • WildTangent, Inc.
File Description
  • Updater
  • WTDownloader
File Version
  • 1.0.4.228
  • 1.0.1.327
Internal Name Updater.exe
Legal Copyright
  • Copyright (C) 2015
  • WildTangent, Inc. All rights reserved.
Original Filename Updater.exe
Product Name Updater
Product Version
  • 1.0.4.228
  • 1.0.1.327

File Traits

  • 2+ executable sections
  • HighEntropy
  • packed
  • upx
  • UPX!
  • x86

Block Information

Total Blocks: 349
Potentially Malicious Blocks: 49
Whitelisted Blocks: 300
Unknown Blocks: 0

Visual Map

x 0 x x x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 x x 0 0 0 x x x x x x x x x x x x x x x 0 0 x x 0 0 x x x 0 0 0 2 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 1 0 0 1 1 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 1 0 1 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 2 2 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • NtQuerySystemInformation
User Data Access
  • GetComputerNameEx