Trojan

Trojan-Downloader.Win32.Upatre.edv removal tips

Malware Removal

The Trojan-Downloader.Win32.Upatre.edv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.edv virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan-Downloader.Win32.Upatre.edv?


File Info:

name: 3AF9ED52BF00D6DA0D85.mlw
path: /opt/CAPEv2/storage/binaries/614a7d3dd8d13c770208bff765609ac80d13a530f90b86bd3f14074025278f07
crc32: 1CC45332
md5: 3af9ed52bf00d6da0d8501a9dd7af275
sha1: b32aa45571a53faf2f2e62e1fc94237443cd3a41
sha256: 614a7d3dd8d13c770208bff765609ac80d13a530f90b86bd3f14074025278f07
sha512: fae04f8fb877c641787822a0980b89f8cfdc22b8ea2af74c8f777660a2bfb80ad6a00fd66fdedb3d3f4cf654d5258b0eee44d84d55597ebc7a928eed581e7b05
ssdeep: 192:jTU9g9cVUz0wgJMGNT5NzNkFsZP1oynw0UWdto9KZjzqI/V2+m6DeVo9tlwNMm:cVk0wrG7NRkSl16t8to9KJzqIE+m4wZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14AA2B39A52D1793CD1660E7A15E2C7864634BC212F5982CF7E4CF508B83FAC3A8F075A
sha3_384: 114826e3ee08afbc59b4adc6e6c359b5fe9abcb7f77aadf1bba090e7d97fd03d2dd85543b4a69dfa2f70cace7c94932c
ep_bytes: 53b8ffff0010e8a2f9ffff5bc3ccff25
timestamp: 1995-08-29 04:02:04

Version Info:

FileDescription: JuJu
FileVersion: 2.1.2.11
LegalCopyright: Copyright 2009-2013 all authors
OriginalFilename: JuJu.exe
ProductName: JuJu
ProductVersion: 2.1.2.11
CompanyName: JuJu corporation
Translation: 0x0411 0x04b2

Trojan-Downloader.Win32.Upatre.edv also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BFBM
FireEyeGeneric.mg.3af9ed52bf00d6da
CAT-QuickHealTrojanDownloader.Upatre.AA4
ALYacTrojan.Agent.BFBM
CylanceUnsafe
VIPRETrojan.Win32.Upatre.buu (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
BitDefenderTrojan.Agent.BFBM
K7GWTrojan-Downloader ( 0055e3da1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.16E5CF4E1F
VirITTrojan.Win32.Generic.AW
CyrenW32/Trojan.RFPS-5185
SymantecBackdoor.Trojan
ESET-NOD32Win32/TrojanDownloader.Waski.A
BaiduWin32.Trojan-Downloader.Waski.a
TrendMicro-HouseCallTROJ_UPATRE.SM37
ClamAVWin.Downloader.Upatre-5744092-0
KasperskyTrojan-Downloader.Win32.Upatre.edv
NANO-AntivirusTrojan.Win32.Cryptodef.demivm
RisingDownloader.Waski!8.184 (RDMK:cmRtazobvvZ8JB3Oon5C32H/D1Hw)
Ad-AwareTrojan.Agent.BFBM
SophosML/PE-A + Troj/Upatre-EU
ComodoTrojWare.Win32.TrojanDownloader.Waski.DA@5iyglc
DrWebTrojan.DownLoader11.30467
ZillyaTrojan.Cryptodef.Win32.186
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionDownloader-FSH!3AF9ED52BF00
EmsisoftTrojan.Agent.BFBM (B)
APEXMalicious
GDataTrojan.Agent.BFBM
JiangminTrojan/Cryptodef.ax
eGambitUnsafe.AI_Score_83%
AviraHEUR/AGEN.1120686
Antiy-AVLTrojan/Generic.ASMalwS.BC9D18
MicrosoftTrojanDownloader:Win32/Upatre
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.C535016
Acronissuspicious
McAfeeDownloader-FSH
MAXmalware (ai score=80)
VBA32Hoax.Cryptodef
MalwarebytesTrojan.Upatre
IkarusTrojan.Win32.Bublik
PandaTrj/Genetic.gen
TencentTrojan-Downloader.Win32.Waski.16000151
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr.dldr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Trojan-Downloader.Win32.Upatre.edv?

Trojan-Downloader.Win32.Upatre.edv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment