Trojan

Trojan.Downloader.RRE removal

Malware Removal

The Trojan.Downloader.RRE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.RRE virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Downloader.RRE?


File Info:

name: BB642FA57A46DD01BA50.mlw
path: /opt/CAPEv2/storage/binaries/dd31bcbb92e997d71fe40551e76aab2044ba427bff730749f747c201fce5c00b
crc32: B85CA5CB
md5: bb642fa57a46dd01ba50116af814a24e
sha1: a79501ced95e7120bd6c51a84b1e2b1b298f1e1f
sha256: dd31bcbb92e997d71fe40551e76aab2044ba427bff730749f747c201fce5c00b
sha512: 27a12c8bb33654e7036f32dd5deb4dea6f502442b1bc3db5a3cbe2464986c4284eca510e645a94c7814223a7219e4b998c1bfeacf238123a5ef98807b2a28b45
ssdeep: 384:UDUD00+G0jHXRrs905INeZCFtejlIko5dN127BFVn2p4lAnZ8t1IBCd91NzDFRp:ZiNjHXRrs9sINeZEtejlIkoLN127BFVf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BC8295B0BFC558E9E62351B3F8F7D5C160577E9AA1275A0CA5A17F0689F3243B0A1C0B
sha3_384: 371c5debc761ba6c74d20111b7450a5ec49add35001ade97bceb69b8d90c9cd064db6825d4af119f65dc22fe40590b04
ep_bytes: e8f9fbffffeb5133c0c35753508bd885
timestamp: 2005-12-14 17:33:00

Version Info:

0: [No Data]

Trojan.Downloader.RRE also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.bb642fa57a46dd01
CAT-QuickHealTrojanDownloader.Upatre.A4
McAfeeDownloader-FSH
CylanceUnsafe
VIPRETrojan.Win32.Upatre.jr (v)
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.Ppatre.Gen.1
K7GWTrojan ( 0001140e1 )
K7AntiVirusTrojan ( 0001140e1 )
BitDefenderThetaGen:NN.ZexaF.34182.bqX@ae2rfbdi
VirITTrojan.Win32.Generic.ARCP
CyrenW32/A-5d97632c!Eldorado
SymantecDownloader.Upatre!gen5
ESET-NOD32Win32/TrojanDownloader.Waski.A
TrendMicro-HouseCallTROJ_UPATRE.SM37
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Bublik.cubrdv
TencentMalware.Win32.Gencirc.10b8bc9e
Ad-AwareTrojan.Ppatre.Gen.1
EmsisoftTrojan.Ppatre.Gen.1 (B)
ComodoTrojWare.Win32.Upatre.O@58re0o
BaiduWin32.Trojan-Downloader.Waski.a
ZillyaTrojan.Zbot.Win32.149557
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.lm
SophosML/PE-A + Mal/Upatre-A
GDataWin32.Trojan-Downloader.Upatre.BK
JiangminTrojan-Spy.Win32.Zbot.h
Webroot
AviraTR/Yarwi.AD.113
Antiy-AVLTrojan/Generic.ASMalwS.899DE0
KingsoftHeur.SSC.2727763.0010.(kcloud)
ArcabitTrojan.Ppatre.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDownloader:Win32/Upatre.AA
AhnLab-V3Trojan/Win32.Zbot.R100997
Acronissuspicious
VBA32BScope.TrojanSpy.Zbot
ALYacTrojan.Ppatre.Gen.1
MAXmalware (ai score=89)
MalwarebytesTrojan.Downloader.RRE
PandaGeneric Suspicious
APEXMalicious
RisingSpyware.Zbot!8.16B (TFE:dGZlOgJva1IbKkJzKA)
YandexTrojan.Bublik!hNJnlYvDc2I
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Agent-AUID [Trj]
Cybereasonmalicious.57a46d
AvastWin32:Agent-AUID [Trj]

How to remove Trojan.Downloader.RRE?

Trojan.Downloader.RRE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment