Trojan

Trojan-Downloader.Win32.Upatre.cmrs removal instruction

Malware Removal

The Trojan-Downloader.Win32.Upatre.cmrs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.cmrs virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan-Downloader.Win32.Upatre.cmrs?


File Info:

name: 1A479B4C3B7156496AE3.mlw
path: /opt/CAPEv2/storage/binaries/4112a48e1acde7ecc5b0a927660d24223c23e06ab9c72f39ebf4237f008db185
crc32: 83368D1A
md5: 1a479b4c3b7156496ae307542536fbe0
sha1: 82a9f85894de31b6dcb025fc5f26b4b4a06b7b1f
sha256: 4112a48e1acde7ecc5b0a927660d24223c23e06ab9c72f39ebf4237f008db185
sha512: 2c5478b4d793fb6a344e96df32a4c7a539a4e87edb949c98e08dbc0e318671bcd1229b08911f48c0e46bc0685eafa107bf94abf71b6d2ea9f1afafaa036f044e
ssdeep: 1536:kYuWZcSAo2ZXPCP6X+lICL5pX4AN+XWjKELEUGua1m:krJX+f5pX4AN+mjKbUu1m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D636B137384C5B6F82241744879D661675FBC1627A0428F3F8D7B6E5EB23824ABB31B
sha3_384: 762d33f04b1f842cf967e72ca8befe02f7c6fb9ea6352a835f53d81416da77a89cf573bc748b0ca85b907a74055c0352
ep_bytes: e8f4150000e978feffff8bff558bec8b
timestamp: 2014-05-07 19:36:59

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Upatre.cmrs also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Upatre.Gen.3
CAT-QuickHealTrojan.Necurs.MUE.A4
ALYacTrojan.Upatre.Gen.3
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.UpatreGen.Win32.90
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004c75411 )
K7AntiVirusTrojan ( 004c75411 )
BaiduWin32.Trojan.Kryptik.jr
VirITTrojan.Win32.Generic.EXH
CyrenW32/Upatre.BE.gen!Eldorado
SymantecDownloader.Upatre!gen5
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.DOJF
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Upatre.cmrs
BitDefenderTrojan.Upatre.Gen.3
NANO-AntivirusTrojan.Win32.Upatre.dtlvmb
SUPERAntiSpywareTrojan.Agent/Gen-DownloaderUpatre
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.hae
EmsisoftTrojan.Upatre.Gen.3 (B)
F-SecureTrojan-Downloader:W32/Upatre.P
DrWebTrojan.DownLoader14.38521
VIPRETrojan.Upatre.Gen.3
TrendMicroTROJ_HPUPATRE.SML1
McAfee-GW-EditionBehavesLike.Win32.Upatre.kh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1a479b4c3b715649
SophosTroj/Upatre-OS
SentinelOneStatic AI – Malicious PE
GDataTrojan.Upatre.Gen.3
JiangminTrojan/Generic.bgsjz
WebrootW32.Trojan.Gen
AviraTR/Dldr.Upatre.MU
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Kryptik.dojf
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.DOM@5st38w
ArcabitTrojan.Upatre.Gen.3
ZoneAlarmTrojan-Downloader.Win32.Upatre.cmrs
MicrosoftTrojanDownloader:Win32/Upatre
GoogleDetected
AhnLab-V3Trojan/Win32.Upatre.R155998
Acronissuspicious
McAfeeUpatre-FACQ!1A479B4C3B71
VBA32TrojanDownloader.Upatre
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_HPUPATRE.SML1
RisingMalware.FakePDF/ICON!1.A24C (CLASSIC)
YandexTrojan.DL.Upatre!8DqrLN6214Q
IkarusTrojan.Win32.Waski
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.DQAA!tr
BitDefenderThetaGen:NN.ZexaF.36738.eqX@a4pzKRbO
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.894de3
DeepInstinctMALICIOUS

How to remove Trojan-Downloader.Win32.Upatre.cmrs?

Trojan-Downloader.Win32.Upatre.cmrs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment