Trojan

TrojanDownloader:Win32/Upatre.J removal guide

Malware Removal

The TrojanDownloader:Win32/Upatre.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre.J virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Upatre.J?


File Info:

name: 8F1628F8AF7E936AA9F8.mlw
path: /opt/CAPEv2/storage/binaries/ab0bb62f5c28e1522863d132d16a4cf755a8fe9b0b1f08eb0f5f25dfbb7eb7a5
crc32: 7C02264E
md5: 8f1628f8af7e936aa9f8fdc2f73a27fb
sha1: 6c7667f40440ed452528aff286c24f8fb6b24797
sha256: ab0bb62f5c28e1522863d132d16a4cf755a8fe9b0b1f08eb0f5f25dfbb7eb7a5
sha512: 1b7358cc51df0557ba46923cf82228fe94661d58cc790686dfefe43d23b376985142cd0d8315d770e04f8b3393c7a7aa5fd9a0a359ea47e87a93faf861023ca1
ssdeep: 384:DwrQ9IDJBFgaAY1ytMrcU4Q99999999/i6wEKCMfxrZYSyO0AAkJ22tO4WXY:U4ItBuaAYQY4Q99999999/iDEKCMfxrn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T105A254346DD29AB6D3B7CA72C4F3DDD7A5637D6230122B0E688357160A33A0A7CC195E
sha3_384: e4f0749689a2a1d3f88904d7ad0c38012d7b9f7a7dbd9c77e0153c6817005ea537e0c69ccfe7a9ed4ec93be35410de7f
ep_bytes: 558bec83ec4456ff15083040008bf08a
timestamp: 2013-12-18 09:11:54

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre.J also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.1462257
FireEyeGeneric.mg.8f1628f8af7e936a
CAT-QuickHealTrojanDownloader.Upatre.A4
ALYacTrojan.GenericKD.1462257
CylanceUnsafe
VIPRETrojan.Win32.Upatre.jr (v)
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.1462257
K7GWTrojan-Downloader ( 0048f6391 )
K7AntiVirusTrojan-Downloader ( 0048f6391 )
BitDefenderThetaGen:NN.ZexaF.34182.bqX@aumOaudi
VirITTrojan.Win32.Generic.AUAL
CyrenW32/Trojan.BQZG-6160
SymantecDownloader.Upatre
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Downloader.Upatre-5744092-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Waski.crhesw
RisingDownloader.Waski!1.A489 (RDMK:cmRtazofZEKJdRs5twLSyI6j3c0q)
Ad-AwareTrojan.GenericKD.1462257
SophosML/PE-A + Troj/Dapato-AV
BaiduWin32.Trojan-Downloader.Waski.a
DrWebTrojan.DownLoad3.28161
ZillyaTrojan.Bublik.Win32.12650
TrendMicroTROJ_UPATRE.SMBX
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.mm
EmsisoftTrojan.GenericKD.1462257 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Bublik.glb
AviraTR/Crypt.XPACK.37177
Antiy-AVLTrojan/Generic.ASMalwS.68E362
MicrosoftTrojanDownloader:Win32/Upatre.J
ArcabitTrojan.Generic.D164FF1
SUPERAntiSpywareTrojan.Agent/Gen-Bublik
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Upatre.BK
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dapato.R92734
Acronissuspicious
McAfeeDownloader-FSH
MAXmalware (ai score=86)
VBA32BScope.TrojanSpy.Zbot
MalwarebytesTrojan.Email.FakeDoc
PandaTrj/Downloader.WKY
TrendMicro-HouseCallTROJ_UPATRE.SMBX
TencentTrojan.Win32.Downloader.wc
IkarusTrojan-Downloader.Win32.Upatre
FortinetW32/Waski.A!tr
AVGWin32:Agent-ASSV [Trj]
Cybereasonmalicious.8af7e9
AvastWin32:Agent-ASSV [Trj]
MaxSecureTrojan.Upatre.Gen

How to remove TrojanDownloader:Win32/Upatre.J?

TrojanDownloader:Win32/Upatre.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment