Malware

Should I remove “Troj/Upatre-YW”?

Malware Removal

The Troj/Upatre-YW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Upatre-YW virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings

How to determine Troj/Upatre-YW?


File Info:

name: F964DBABD19D86BB7856.mlw
path: /opt/CAPEv2/storage/binaries/84f2461fc3e2fedf5c359ca6f80a395191fe4a9acbbd85053464846df57d53a3
crc32: 88C1A020
md5: f964dbabd19d86bb78566e7e641b1ad7
sha1: 66b91ba97cfee1d978e3572bc589a3cd8de84a90
sha256: 84f2461fc3e2fedf5c359ca6f80a395191fe4a9acbbd85053464846df57d53a3
sha512: 12e58874407491efdd248c9bbd488bcc8d5fd605fcd1d42f999788ed474d1b12f6a4a7e640661e5cf11a7277fa40605892f9c4545db683b831035520578071f5
ssdeep: 96:rlRc6dTc3D0it64aVSTmt+kFuVEETEl4EnQ1hkwPFSDWYGXIPbxw5y7DUuH1QrSI:3SXtoITYiIznYhkwP6TfUcM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1550268386FE95572E3BBCF7589F551C6BA74B4227D06994D409A43880823FA2DDB0A0E
sha3_384: 65fa5950ea9b353c4980c186f6f244079ab2af554b3e15f310d8a118fcd9c9da62b3b04103200f6aba6f79d80d7971b2
ep_bytes: 558becb83c200000e863030000535657
timestamp: 2013-09-06 09:44:54

Version Info:

0: [No Data]

Troj/Upatre-YW also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.f964dbabd19d86bb
ALYacTrojan.Ppatre.Gen.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0050fef41 )
K7GWTrojan-Downloader ( 00456a071 )
Cybereasonmalicious.bd19d8
BitDefenderThetaGen:NN.ZexaE.36308.amX@ayjVPSi
VirITTrojan.Win32.Upatre.AJ
CyrenW32/Upatre.LX.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Small.PRL
APEXMalicious
ClamAVWin.Downloader.Upatre-9952018-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad3.dofdyx
TencentTrojan-DL.Win32.Small.yw
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Ppatre.Gen.1
McAfee-GW-EditionBehavesLike.Win32.Downloader.xz
Trapminemalicious.high.ml.score
SophosTroj/Upatre-YW
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojanDownloader.Generic.akuo
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.Waski.a
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.ACC@56yhj8
ArcabitTrojan.Ppatre.Gen.1
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
MicrosoftTrojan:Win32/Upatre.MH!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R83549
VBA32BScope.Trojan.Downloader
MAXmalware (ai score=85)
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Agent!1.E264 (CLASSIC)
YandexTrojan.Agent!bKYKQvZLomQ
IkarusTrojan-Downloader.Win32.Upatre
FortinetW32/Tiny.NIV!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Troj/Upatre-YW?

Troj/Upatre-YW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment