Malware

ML/PE-A + Troj/Upatre-AI removal tips

Malware Removal

The ML/PE-A + Troj/Upatre-AI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Upatre-AI virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine ML/PE-A + Troj/Upatre-AI?


File Info:

name: D3DDD4AD666E56BE6EB6.mlw
path: /opt/CAPEv2/storage/binaries/4770b6a580b13e8c6351d7cd6ecc4e64bde2058184743fee26e211a8e8de8269
crc32: BF9B3045
md5: d3ddd4ad666e56be6eb6cc2eacde0174
sha1: 17dfda32278a6ebf24dfc1852a4db7e8875930dd
sha256: 4770b6a580b13e8c6351d7cd6ecc4e64bde2058184743fee26e211a8e8de8269
sha512: ec3e618f8c381fdb34ae77ce3b2c37b0ce6be288c91c709ebf0753c4d5bce137d19280c6a0669b2bcd3c4eb1af52bb4f6b9ae37cfb0034264da48968e0ffa44a
ssdeep: 384:0Krk8DF81knZhKX0GEpfkMP+OijC2WO6O9OcU1lC0A/P1C7sAPR:0KXDaOn7e0LpcOveWl9wdC7sAPR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5A261315BDBCBDDF2334AB6C4B6C1862C64B6A4A865091E5D81360474E3733E89FE4E
sha3_384: 8dda84ff2340871e7ebb8600dec9309697849beb30cfe48dc9e3e82ad3ef2365fa45565fbffbdbc312f243520c6e6de1
ep_bytes: 5383c4bc54ff150c3040008b7424046a
timestamp: 2011-08-07 17:53:52

Version Info:

0: [No Data]

ML/PE-A + Troj/Upatre-AI also known as:

BkavW32.FamVT.GeND.Trojan
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanTrojan.GenericKD.1618307
FireEyeGeneric.mg.d3ddd4ad666e56be
CAT-QuickHealTrojanDownloader.Upatre.A4
McAfeePWS-FBRL
CylanceUnsafe
ZillyaTrojan.Bublik.Win32.13447
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0048f6391 )
K7GWTrojan-Downloader ( 0048f6391 )
Cybereasonmalicious.d666e5
BitDefenderThetaGen:NN.ZexaF.34698.bqX@a4qQK8ji
VirITTrojan.Win32.Generic.CZO
CyrenW32/Trojan.JGRV-1466
SymantecDownloader.Upatre
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Trojan.Upatre-3392
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.1618307
NANO-AntivirusTrojan.Win32.Waski.cvwzco
SUPERAntiSpywareTrojan.Agent/Gen-Bublik
AvastWin32:Agent-AUID [Trj]
TencentMalware.Win32.Gencirc.10b32150
Ad-AwareTrojan.GenericKD.1618307
EmsisoftTrojan.GenericKD.1618307 (B)
ComodoTrojWare.Win32.Bublik.CEZE@595kvx
BaiduWin32.Trojan-Downloader.Waski.a
VIPRETrojan.GenericKD.1618307
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.mm
Trapminesuspicious.low.ml.score
SophosML/PE-A + Troj/Upatre-AI
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.azses
GoogleDetected
AviraTR/Yarwi.ewcbk
Antiy-AVLTrojan/Generic.ASMalwS.555
MicrosoftTrojanDownloader:Win32/Upatre.O
GDataWin32.Trojan-Downloader.Upatre.BK
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R102594
VBA32BScope.TrojanSpy.Zbot
ALYacTrojan.GenericKD.1618307
MAXmalware (ai score=82)
MalwarebytesTrojan.Upatre
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.Bublik!h9c4r+7Z5b8
IkarusTrojan-Downloader.Win32.Upatre
FortinetW32/Upatre.BH!tr
AVGWin32:Agent-AUID [Trj]
PandaTrj/Downloader.WKY
CrowdStrikewin/malicious_confidence_100% (D)

How to remove ML/PE-A + Troj/Upatre-AI?

ML/PE-A + Troj/Upatre-AI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment