Home Malware Programs Trojans Trojan:Win32/Urelas.C

Trojan:Win32/Urelas.C

Posted: December 7, 2012

Threat Metric

Ranking: 10,909
Threat Level: 8/10
Infected PCs: 8,591
First Seen: December 7, 2012
Last Seen: March 8, 2025
OS(es) Affected: Windows

Trojan:Win32/Urelas.C is a Trojan that monitors particular card game applications and transmits screenshots and information about a victimized computer to a remote server. Trojan:Win32/Urelas.C also downloads and installs other security threats on the infected computer system. Once installed, Trojan:Win32/Urelas.C makes system changes by adding potentially malicious files and making registry modifications. Computer users may inadvertently download Trojan:Win32/Urelas.C, thinking it is an application associated with a card game. Trojan:Win32/Urelas.C monitors the processes that belong to particular card games.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



028e31efbe9f6c149fdc45e4c871dc75 File name: 028e31efbe9f6c149fdc45e4c871dc75
Size: 2.2 MB (2207232 bytes)
MD5: 028e31efbe9f6c149fdc45e4c871dc75
Detection count: 85
Group: Malware file
Last Updated: March 5, 2013
ebb3f1255cc4e93bf214050eb6b3f43a File name: ebb3f1255cc4e93bf214050eb6b3f43a
Size: 4.85 MB (4859392 bytes)
MD5: ebb3f1255cc4e93bf214050eb6b3f43a
Detection count: 84
Group: Malware file
Last Updated: March 5, 2013
File.exe File name: File.exe
Size: 192.51 KB (192512 bytes)
MD5: c0cf36675be9d874fc661e67ced26ba1
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 20, 2017
a4240542d114fb332e81efde95a61434 File name: a4240542d114fb332e81efde95a61434
Size: 465.6 KB (465607 bytes)
MD5: a4240542d114fb332e81efde95a61434
Detection count: 82
Group: Malware file
Last Updated: March 5, 2013
7ZSfxNew.exe File name: 7ZSfxNew.exe
Size: 2.2 MB (2200205 bytes)
MD5: b829e686d0e252f6be5c197f156c6745
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 5, 2013
ctfmom.exe File name: ctfmom.exe
Size: 206.97 KB (206976 bytes)
MD5: 4ec7b4a820ab08dbef615fc889e9b1f5
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\awopk.exe File name: awopk.exe
Size: 500.26 KB (500269 bytes)
MD5: c5a65490ab06ce30b1ca4a7afd0bea22
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\awopk.exe
Group: Malware file
Last Updated: June 26, 2020
%TEMP%\_uninsep.bat File name: %TEMP%\_uninsep.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
<system folder>\golfinfo.ini File name: <system folder>\golfinfo.ini
Mime Type: unknown/ini
Group: Malware file
<system folder>\gbp.ini File name: <system folder>\gbp.ini
Mime Type: unknown/ini
Group: Malware file
<system folder>\setup.exe File name: <system folder>\setup.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
<system folder>\MkUpdate.exe File name: <system folder>\MkUpdate.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
<system folder>lymucexuc.dll File name: <system folder>lymucexuc.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
<system folder>lyycofez.exe File name: <system folder>lyycofez.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%TEMP%\_uinsey.bat%TEMP%\golfinfo.ini%TEMP%\hotez.exeHKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost "", for example "Hiceegdiyfp" = "", for example "Jiuswan" HKEY_LOCAL_MACHINE\SOFTWARE\SYSTEM\CurrentControlSet\Services\"HKEY_LOCAL_MACHINE\SOFTWARE\SYSTEM\CurrentControlSet\Services\Jiuswan\Parameters "ServiceDll" = "\.dll", for example "C:\Windows\System32\lymucexuc.dll"
Loading...