Trojan

Trojan-Downloader.Win32.Upatre.bkvd information

Malware Removal

The Trojan-Downloader.Win32.Upatre.bkvd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.bkvd virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Mimics icon used for popular non-executable file format
  • Anomalous binary characteristics

How to determine Trojan-Downloader.Win32.Upatre.bkvd?


File Info:

name: 7C19D21D9731BD8E08C0.mlw
path: /opt/CAPEv2/storage/binaries/a86a04609493fab5aa3c140b278bcabbd309be2e081b7fb10fca25441d082278
crc32: 9F8A6BA9
md5: 7c19d21d9731bd8e08c0088cc220e6b7
sha1: 50c5138ed44f53d25c925a5c870729c797216666
sha256: a86a04609493fab5aa3c140b278bcabbd309be2e081b7fb10fca25441d082278
sha512: 5c5efc7692604e2690796768df72442757ded14317507698cd42aa60bb2fe3edb00730e3de164348ceeeb5fe48d04766126f6750a5ebc4506d1312929bee76ce
ssdeep: 1536:Sl3DUCFbEIpY3RkMx6IsmyKlLdwecDtPgSJManNLVh:mTUCaIpYBxvsmysCrNX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17073E6E9B7D480B2E133B934C4719DD39A3B742F3D60419E16883235BE76BC29E6534A
sha3_384: 15dbd486f070256f857ec6578febb86d2e34b286e91daaf176a163b3de21bfb2a3f051128b082edf949e149b1c286769
ep_bytes: e8cdf2ffffe9b7f3ffffcccccccccccc
timestamp: 2014-07-19 14:19:44

Version Info:

FileDescription: DAVT Corp.
InternalName: DAVT Utility
FileVersion: 1.0.0.10
CompanyName: DAVT
LegalCopyright: Copyright 2014-2015 DAVT
OriginalFilename: davtil.exe
ProductName: DAVT Corp.
ProductVersion: 1.0.0.10
Translation: 0x0423 0x04b1

Trojan-Downloader.Win32.Upatre.bkvd also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Upatre.Gen.3
CAT-QuickHealTrojan.Kadena.B4
SkyhighBehavesLike.Win32.Upatre.lm
ALYacTrojan.Upatre.Gen.3
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPRETrojan.Upatre.Gen.3
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004c75411 )
K7GWTrojan ( 004c5f921 )
Cybereasonmalicious.ed44f5
BitDefenderThetaGen:NN.ZexaF.36680.em1@aWMb2JfG
SymantecDownloader.Upatre!gen5
ESET-NOD32a variant of Win32/Kryptik.DMJN
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Upatre.bkvd
BitDefenderTrojan.Upatre.Gen.3
NANO-AntivirusTrojan.Win32.Upatre.dthtbs
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b2666b
EmsisoftTrojan.Upatre.Gen.3 (B)
BaiduWin32.Trojan.Kryptik.jn
F-SecureTrojan.TR/Kryptik.abboik
DrWebTrojan.Upatre.3504
ZillyaDownloader.Upatre.Win32.37543
TrendMicroTROJ_UPATRE.SM37
SophosTroj/Dyreza-FP
IkarusPUA.Bundler
JiangminTrojanDownloader.Upatre.adqh
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraTR/Kryptik.abboik
Antiy-AVLTrojan[Downloader]/Win32.Upatre.bkvd
Kingsoftmalware.kb.a.998
MicrosoftTrojanDownloader:Win32/Upatre
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.KMJ@5s5qya
ArcabitTrojan.Upatre.Gen.3
ZoneAlarmTrojan-Downloader.Win32.Upatre.bkvd
GDataWin32.Trojan-Downloader.Upatre.BK
VaristW32/Upatre.AT.gen!Eldorado
AhnLab-V3Trojan/Win32.Upatre.R154505
Acronissuspicious
McAfeeUpatre-FACM!7C19D21D9731
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Waski.A!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Downloader.Win32.Upatre.bkvd?

Trojan-Downloader.Win32.Upatre.bkvd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment