Malware

ML/PE-A + Troj/Upatre-NY removal instruction

Malware Removal

The ML/PE-A + Troj/Upatre-NY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Upatre-NY virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Urdu (Pakistan)
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
icanhazip.com

How to determine ML/PE-A + Troj/Upatre-NY?


File Info:

crc32: 360E5075
md5: d4d4e386aba2ad30baedc95aa3dd2cc8
name: D4D4E386ABA2AD30BAEDC95AA3DD2CC8.mlw
sha1: 79b14637929f6870b64821a707c495c7aaf4d128
sha256: b441148ef4a3b7f4227096551721026b940f00d69a3fbf74dbbf359dcd8ccd68
sha512: 86b6a8381d9ad9c4efca83eedd5b98263137e64c34da0746baafde4697eed00749fc511f2894dbcca2afbcb457daf90820fcbdf07a8cc40ae21816b046dd1f5a
ssdeep: 1536:Itka3G9MXSRa+ycuCRo0oxNqIxSupVvIY:Qka29MXZxIY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

ML/PE-A + Troj/Upatre-NY also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004c75411 )
Elasticmalicious (high confidence)
DrWebTrojan.Upatre.3341
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Kadena.B4
ALYacTrojan.Upatre.Gen.3
CylanceUnsafe
ZillyaDownloader.UpatreGen.Win32.23
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004c75411 )
Cybereasonmalicious.6aba2a
BaiduWin32.Trojan.Kryptik.jw
CyrenW32/Upatre.AS.gen!Eldorado
SymantecDownloader.Upatre!gen5
ESET-NOD32a variant of Win32/Kryptik.DLZD
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Downloader.Upatre-5744087-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Upatre.Gen.3
NANO-AntivirusTrojan.Win32.Upatre.dssjpt
MicroWorld-eScanTrojan.Upatre.Gen.3
TencentTrojan.Win32.Kryptik.dlzda
Ad-AwareTrojan.Upatre.Gen.3
SophosML/PE-A + Troj/Upatre-NY
ComodoTrojWare.Win32.TrojanDownloader.Upatre.NY@5s465i
BitDefenderThetaGen:NN.ZexaF.34236.dqX@auWsu7mG
VIPRETrojan.Win32.Upatre.bv (v)
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Duptwux.qm
FireEyeGeneric.mg.d4d4e386aba2ad30
EmsisoftTrojan.Upatre.Gen.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Upatre.msn
AviraTR/Downloader.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.119C64C
MicrosoftTrojanDownloader:Win32/Upatre.BN
GDataWin32.Trojan-Downloader.Upatre.AE
AhnLab-V3Trojan/Win32.FakeDoc.C885682
Acronissuspicious
McAfeeUpatre-FACM!D4D4E386ABA2
MAXmalware (ai score=80)
VBA32Trojan.Upatre
MalwarebytesTrojan.Upatre.VT
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Upatre!1.A19D (CLASSIC)
YandexTrojan.GenAsa!F+MDvoMFOVU
IkarusTrojan-Banker.TrickBot
FortinetW32/Daserf.B!tr
AVGWin32:Trojan-gen

How to remove ML/PE-A + Troj/Upatre-NY?

ML/PE-A + Troj/Upatre-NY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment