Malware

ML/PE-A + Troj/Upatre-EU removal instruction

Malware Removal

The ML/PE-A + Troj/Upatre-EU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Upatre-EU virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine ML/PE-A + Troj/Upatre-EU?


File Info:

name: 7ABBE2A5EE6A56AA479F.mlw
path: /opt/CAPEv2/storage/binaries/4b8a04c1cf8b51fe31646fb34ecb6fb86a92dc0a90c354b7d5e844ea119087f2
crc32: 8591D270
md5: 7abbe2a5ee6a56aa479ffcdd4f5775af
sha1: d5db7d1a1f03f618caf9c048d416838c9ac54fd1
sha256: 4b8a04c1cf8b51fe31646fb34ecb6fb86a92dc0a90c354b7d5e844ea119087f2
sha512: cddea4bc6cfabd9c8aef91ab604c6e7a6a9eb964717759bbf6e379bc3510ba1cbdf2009be7183c8ca0b2421f374ea0a64568cca4a5b59486423a61f2d0e3190d
ssdeep: 192:jTU9g9cVUz0wgJMGNT5NzNkFsZP1oynw0UWdto9KZjzqI/V2+m6DeVoCWV:cVk0wrG7NRkSl16t8to9KJzqIE+mdy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8A2B29A52D1793CE1660E7A15F2D7864634BC212F4A82CF7E4CF508B87F6C3A8B0756
sha3_384: 53953168cc5a4f665c1df33efadb61915e9a0a75c4e9f409a1d1abcbefb11cb274f35e15f8ff49060c4e48801d22c3ca
ep_bytes: 53b8ffff0010e8a2f9ffff5bc3ccff25
timestamp: 1995-08-29 04:02:04

Version Info:

FileDescription: JuJu
FileVersion: 2.1.2.11
LegalCopyright: Copyright 2009-2013 all authors
OriginalFilename: JuJu.exe
ProductName: JuJu
ProductVersion: 2.1.2.11
CompanyName: JuJu corporation
Translation: 0x0411 0x04b2

ML/PE-A + Troj/Upatre-EU also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader11.30467
MicroWorld-eScanTrojan.Agent.BFBM
FireEyeGeneric.mg.7abbe2a5ee6a56aa
CAT-QuickHealTrojanDownloader.Upatre.AA4
ALYacTrojan.Agent.BFBM
CylanceUnsafe
VIPRETrojan.Win32.Upatre.buu (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
BitDefenderTrojan.Agent.BFBM
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.5ee6a5
BitDefenderThetaAI:Packer.16E5CF4E1F
VirITTrojan.Win32.Generic.AW
CyrenW32/Trojan.RFPS-5185
SymantecBackdoor.Trojan
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Downloader.Upatre-5744092-0
KasperskyTrojan-Downloader.Win32.Upatre.edv
NANO-AntivirusTrojan.Win32.Cryptodef.demivm
RisingDownloader.Waski!8.184 (RDMK:cmRtazobvvZ8JB3Oon5C32H/D1Hw)
Ad-AwareTrojan.Agent.BFBM
SophosML/PE-A + Troj/Upatre-EU
ComodoTrojWare.Win32.TrojanDownloader.Waski.DA@5iyglc
BaiduWin32.Trojan-Downloader.Waski.a
ZillyaTrojan.Cryptodef.Win32.186
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionDownloader-FSH!7ABBE2A5EE6A
EmsisoftTrojan.Agent.BFBM (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Cryptodef.ax
AviraHEUR/AGEN.1120686
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.BC9D18
MicrosoftTrojanDownloader:Win32/Upatre
GDataTrojan.Agent.BFBM
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.C535016
Acronissuspicious
McAfeeDownloader-FSH
VBA32Hoax.Cryptodef
MalwarebytesTrojan.Upatre
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentTrojan-Downloader.Win32.Waski.16000151
YandexTrojan.Cryptodef!QcEcO+hhoLs
IkarusTrojan.Win32.Bublik
eGambitUnsafe.AI_Score_87%
FortinetW32/Waski.A!tr.dldr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (D)
MaxSecureTrojan.Upatre.Gen

How to remove ML/PE-A + Troj/Upatre-EU?

ML/PE-A + Troj/Upatre-EU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment