Trojan

Trojan-Downloader.Win32.Upatre.cmrj removal guide

Malware Removal

The Trojan-Downloader.Win32.Upatre.cmrj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.cmrj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan-Downloader.Win32.Upatre.cmrj?


File Info:

name: D0E707954E62AA740257.mlw
path: /opt/CAPEv2/storage/binaries/3621babc8ad777dda944c9c9acb42d1595434228b9eb7316167eeaa42d913efd
crc32: E1B8E5D6
md5: d0e707954e62aa74025774a197e0387c
sha1: 869a6a8ca6968748eda85c4739e02183979928d2
sha256: 3621babc8ad777dda944c9c9acb42d1595434228b9eb7316167eeaa42d913efd
sha512: fd4dd92c68c5a5996ad50e57ccaf7ffc3d0fdd0d0691accf5176114cd076082044dfb348c4e88880fb227d9c501ae3e99200d9f832cdfa0db5491460d96f8087
ssdeep: 1536:UyqAXcrg4uQHPSC/+C4O1xLXuGNl7DDhlQeU79WwZ3:U3B/+UxLXuGNlHDhpUkwJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T157635B2277C085B7F833417448BAC5A1675BBC5226A0458F3E8E771E4EB23925DBB31B
sha3_384: 3c21e248ebc0430a4ecbef44d6911033dc21b3f76a01a6e28c2b48648fac301af807ff473d7cd2fbd07084b859756c91
ep_bytes: e8f4150000e978feffff8bff558bec8b
timestamp: 2013-05-25 02:34:52

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Upatre.cmrj also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Upatre.Gen.3
FireEyeGeneric.mg.d0e707954e62aa74
CAT-QuickHealTrojan.Kadena.B4
McAfeeUpatre-FACQ!D0E707954E62
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPRETrojan.Upatre.Gen.3
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004c75411 )
K7GWTrojan ( 004c75411 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36196.eqX@amB9Y9aO
VirITTrojan.Win32.Generic.EXH
CyrenW32/Upatre.BE.gen!Eldorado
SymantecDownloader.Upatre!gen5
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.DOJF
APEXMalicious
KasperskyTrojan-Downloader.Win32.Upatre.cmrj
BitDefenderTrojan.Upatre.Gen.3
NANO-AntivirusTrojan.Win32.Upatre.dtlybx
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10be8c7a
EmsisoftTrojan.Upatre.Gen.3 (B)
BaiduWin32.Trojan.Kryptik.jr
F-SecureTrojan-Downloader:W32/Upatre.P
DrWebTrojan.DownLoader16.239
ZillyaDownloader.UpatreGen.Win32.90
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
SophosTroj/Upatre-OS
IkarusTrojan.Win32.Waski
GDataTrojan.Upatre.Gen.3
JiangminTrojan/Generic.bgsjz
GoogleDetected
AviraTR/Dldr.Upatre.MU
Antiy-AVLTrojan[Downloader]/Win32.Upatre
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.DOM@5st38w
ArcabitTrojan.Upatre.Gen.3
ZoneAlarmTrojan-Downloader.Win32.Upatre.cmrj
MicrosoftTrojanDownloader:Win32/Upatre
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R155998
Acronissuspicious
VBA32BScope.TrojanDownloader.Upatre
ALYacTrojan.Upatre.Gen.3
MAXmalware (ai score=84)
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingMalware.FakePDF/ICON!1.A24C (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.DQAA!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.54e62a
DeepInstinctMALICIOUS

How to remove Trojan-Downloader.Win32.Upatre.cmrj?

Trojan-Downloader.Win32.Upatre.cmrj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment