Threat Database Trojans Trojan.Urelas.LB

Trojan.Urelas.LB

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 7
First Seen: June 1, 2025
Last Seen: October 28, 2025
OS(es) Affected: Windows

The detection of Trojan.Urelas.LB on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Urelas.LB?

Trojan.Urelas.LB is a type of Trojan malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan" comes from the Trojan Horse legend, where a seemingly harmless gift conceals a dangerous threat. In the context of computer security, Trojans are used to describe malware that tricks users into installing it, often by masquerading as a useful application or software update. Once installed, Trojans can cause a wide range of problems, from data theft and system crashes to the installation of additional malware.

How Trojan.Urelas.LB Operates

While the specific details of how Trojan.Urelas.LB operates are not available, Trojans in general typically work by exploiting vulnerabilities in software or human psychology. They may use social engineering tactics to trick users into installing them, such as posing as a legitimate program or attachment in an email. Once installed, Trojans can communicate with their creators, allowing them to remotely control the infected computer, steal sensitive information, or use the computer as a botnet to distribute spam or malware. Trojans can also install additional malware, such as keyloggers, ransomware, or spyware, to further compromise the security of the infected system.

Symptoms of Infection

The symptoms of a Trojan.Urelas.LB infection can vary, but common indicators include unusual system behavior, such as slow performance, frequent crashes, or unexpected pop-ups. You may also notice that your browser homepage has changed, or that you are being redirected to unwanted websites. In some cases, Trojans can also cause problems with your internet connection, such as slow speeds or frequent disconnections. If you suspect that your system is infected with Trojan.Urelas.LB, it is crucial to take immediate action to remove the malware and prevent further damage.

How to Remove Trojan.Urelas.LB

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware that may be present.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time of the infection.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Urelas.LB from your system requires a combination of technical knowledge and caution. By following the steps outlined above and using reputable anti-malware tools, you can help to ensure that your system is clean and secure. However, prevention is always the best approach, and taking steps to protect your system from future infections, such as keeping your software up to date, using strong passwords, and being cautious when installing new programs or opening attachments, is essential to maintaining the security and integrity of your computer.

Analysis Report

General information

Family Name: Trojan.Urelas.LB
Signature status: Modified signature

Known Samples

MD5: 8325d7ad9f68d0ab046f997640e036e0
SHA1: a414f49a42676700b4cf88cddefdb45279228877
SHA256: A40C788DD22E5C530DBFF7D9B40D97C6B8558C2F831575F847EA3D796C54571F
File Size: 697.38 KB, 697376 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Bkav Corporation
File Description Chim Lac Update Setup
File Version 1.3.27.17
Internal Name Chim Lac Update Setup
Language Id en
Legal Copyright Copyright 2013 Bkav Corporation
Original Filename ChimLacUpdateSetup.exe
Product Name Chim Lac Update
Product Version 1.3.27.17

File Traits

  • HighEntropy
  • Installer Version
  • x86

Block Information

Total Blocks: 283
Potentially Malicious Blocks: 4
Whitelisted Blocks: 279
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 1 0 0 1 0 0 0 1 0 0 1 0 0 0 2 2 0 0 1 0 0 0 1 1 1 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 2 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 1 1 1 0 0 0 0 1 0 0 0 0 2 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 1 1 0 0 0 2 0 2 0 0 2 0 0 0 0 1 0 0 0 0 0 1 1 0 1 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_update.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_am.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_ar.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_bg.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_bn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_ca.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_cs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_da.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_de.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_el.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_en-gb.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_en.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_es-419.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_es.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_et.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_fa.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_fi.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_fil.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_fr.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_gu.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_hi.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_hr.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_hu.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_id.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_is.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_it.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_iw.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_ja.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_kn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_ko.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_lt.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_lv.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_ml.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_mr.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_ms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_nl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_no.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_pl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_pt-br.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_pt-pt.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_ro.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_ru.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_sk.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_sl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_sr.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_sv.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_sw.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_ta.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_te.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_th.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_tr.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_uk.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_ur.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_vi.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_zh-cn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlac_updateres_zh-tw.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlaccrashhandler.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlacupdate.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlacupdatebroker.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlacupdatehelper.msi Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\chimlacupdateondemand.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\npchimlacupdate3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\psmachine.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gum5dd0.tmp\psuser.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gut5dd1.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\systemcertificates\authroot\certificates\e12dfb4b41d7d9c32b30514bac1d81d8385e2d46::blob �ZX�͒d{�S�����$� *Sectigo (UTN Object) "0 + +�7 +b o�x�� �Yw�Y�Z�j=�T ��`xu���dt�<�ݙ��[(M�<������Y���,�g~c��&� RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\authroot\certificates\4eb6d578499b1ccf5f581ead56be3d9b6744a5e5::blob ់㇤㹧ৢ䗾鍗૳ᳺứ霞輫穆轙⊩㢅즔Sc愰ℰଆ虠ňŅᜇ〆〒ؐ⬊ĆĄ㞂ļ́ダ؟怉䢆蘁泽ĂሰူਆثЁ舁㰷āȃ쀀ᬰԆ腧Č〃〒ؐ⬊ĆĄ㞂ļ́翀Ā⨀ ب⬈Ćԅ̇؂⬈Ćԅ̇؃⬈Ćԅ̇؄⬈Ćԅ̇ँĀ⨀ ب⬈Ćԅ̇؂⬈Ćԅ RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\authroot\certificates\4eb6d578499b1ccf5f581ead56be3d9b6744a5e5::blob \ص�6�hbu�B�Ҫ�7N��xI��_X�V�=�gD��h~�/-������\L�A��T�a VeriSign�e�����0 �C9��313b �ϫ~C�؀�k&*����e������d��� *0( RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\authroot\certificates\e12dfb4b41d7d9c32b30514bac1d81d8385e2d46::blob �C�;R�)�Hɱ�(�-�KA���+0QK���8^-Fh@� �5�~c��&�����Y���,�g��dt�<�ݙ��[(M�<��b o�x�� �Yw�Y�Z�j=�T ��`xu� "0 + +�7 +  RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\authroot\certificates\e12dfb4b41d7d9c32b30514bac1d81d8385e2d46::blob ���AP0k�㴜���ZX�͒d{�S�����$� *Sectigo (UTN Object) "0 + +�7 +b o�x�� �Yw�Y�Z�j=�T ��`xu���dt�<�ݙ��[(M�<������Y� RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\authroot\certificates\e12dfb4b41d7d9c32b30514bac1d81d8385e2d46::blob \�C�;R�)�Hɱ�(�-�KA���+0QK���8^-Fh@� �5�~c��&�����Y���,�g��dt�<�ݙ��[(M�<��b o�x�� �Yw�Y�Z�j=�T ��`xu� "0 + +�7  RegNtPreCreateKey
HKCU\software\bkav corporation\update\clientstate\{c21db7bf-3628-4ce1-9f47-f9791edd51fd}::usagestats  RegNtPreCreateKey
HKCU\software\bkav corporation\update::uid {398657BF-9281-43AF-A051-570E0DDF81B7} RegNtPreCreateKey
HKCU\software\bkav corporation\update\usagestats\daily::lasttransmission �h RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Cert Store Read
  • CertEnumCertificatesInStore
Anti Debug
  • IsDebuggerPresent
  • OutputDebugString
User Data Access
  • GetComputerNameEx
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

C:\Users\Bolylydw\AppData\Local\Temp\GUM5DD0.tmp\ChimLacUpdate.exe /installsource taggedmi /install "appguid={C21DB7BF-3628-4CE1-9F47-F9791EDD51FD}&needsadmin=False&lang=vi&usagestats=1&channel=stable"
"C:\Users\Bolylydw\AppData\Local\Bkav Corporation\Update\ChimLacUpdate.exe" /unregserver

Trending

Most Viewed

Loading...