Malware

Downldr.Upatre.S29950202 removal guide

Malware Removal

The Downldr.Upatre.S29950202 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downldr.Upatre.S29950202 virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Downldr.Upatre.S29950202?


File Info:

name: CF4DD61490C9E0A0A217.mlw
path: /opt/CAPEv2/storage/binaries/9322ad6aa2358bb612dde74e300999132eb9e97ecec0c295755944cb47a24088
crc32: 9698D710
md5: cf4dd61490c9e0a0a217a2402e5a926a
sha1: 01daabef7d429bc79f2be1b297f1e8624ca26877
sha256: 9322ad6aa2358bb612dde74e300999132eb9e97ecec0c295755944cb47a24088
sha512: b31a19976d347e6ded32fdd8aef8015ac378a3d5878156a020e77db16e181186009618f15e2ade8ef27afc855ea462f5a4d51d0178359f508c38b3276d002d05
ssdeep: 6144:i7fCyvRlCf56CBDpCvZAbQD2WjybyyyYF5t1oTVwd41S2lNXZF8A0QHO0QLKfbsz:NTFpCZxD2WjV4HWpDSkNJ7LQLKINZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T105B4F115B585C032FA9211310A22EBA24A7F7D755726A4CB6BA43B7DAFB03D1E374307
sha3_384: 9cc410f82da912b127e067b01a0401aa183db9dfc95a05d7ecc42d92b6448ffcad4b89c43a37f44a83f6ea35e571802c
ep_bytes: e824610000e989feffff8bff558bec5d
timestamp: 2003-11-11 14:39:16

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 12.0.4518.1014
InternalName: WinWord
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: 2007 Microsoft Office system
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Downldr.Upatre.S29950202 also known as:

BkavW32.AIDetectMalware
DrWebTrojan.Siggen13.11070
MicroWorld-eScanGen:Variant.Zusy.323769
FireEyeGeneric.mg.cf4dd61490c9e0a0
CAT-QuickHealDownldr.Upatre.S29950202
McAfeeGenericRXHF-BX!CF4DD61490C9
Cylanceunsafe
VIPREGen:Variant.Zusy.323769
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 0040f6d71 )
K7GWTrojan ( 005720591 )
Cybereasonmalicious.490c9e
BitDefenderThetaGen:NN.ZexaF.36250.Gu0@amjuzrhi
CyrenW32/Upatre.PH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.QGO
APEXMalicious
ClamAVWin.Trojan.Cuegoe-6336261-0
KasperskyHEUR:Trojan-Dropper.Win32.Agent.gen
BitDefenderGen:Variant.Zusy.323769
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Agent-AYZG [Cryp]
TencentTrojan.Win32.Salgorea.ya
EmsisoftGen:Variant.Zusy.323769 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
ZillyaDropper.Agent.Win32.511438
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.high.ml.score
SophosMal/Horst-E
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.168GMQ4
JiangminTrojan.Generic.hcyf
GoogleDetected
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=85)
Antiy-AVLTrojan[Downloader]/Win32.Upatre
XcitiumApplication.Win32.Amonetize.NE@5te978
ArcabitTrojan.Zusy.D4F0B9
ViRobotTrojan.Win32.Agent.497664.G
ZoneAlarmHEUR:Trojan-Dropper.Win32.Agent.gen
MicrosoftTrojanDownloader:Win32/Upatre
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R546182
Acronissuspicious
VBA32TrojanDownloader.Upatre
ALYacGen:Variant.Zusy.323769
TACHYONTrojan-Dropper/W32.Agent.532480.KG
MalwarebytesWapomi.Virus.FileInfector.DDS
PandaTrj/Genetic.gen
RisingBackdoor.[OceanLotus]Salgorea!1.C3DC (CLASSIC)
YandexTrojan.GenAsa!fgR3yXzCbR8
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Upatre.0285!tr
AVGWin32:Agent-AYZG [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Downldr.Upatre.S29950202?

Downldr.Upatre.S29950202 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment