Trojan

Trojan-Downloader.Win32.Upatre.fdx removal instruction

Malware Removal

The Trojan-Downloader.Win32.Upatre.fdx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.fdx virus can do?

  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Polish
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan-Downloader.Win32.Upatre.fdx?


File Info:

name: 13AFF51E4B26CD20E8AF.mlw
path: /opt/CAPEv2/storage/binaries/0e4d5381c96ace96691abe446187247c47165eb1c55cb43400d780dd2d4f00a2
crc32: EB9CB97F
md5: 13aff51e4b26cd20e8af4ffe0ae10ae8
sha1: 34f8e41616109e9d40ef2d3203eccd769695eebd
sha256: 0e4d5381c96ace96691abe446187247c47165eb1c55cb43400d780dd2d4f00a2
sha512: a34950430fe2537c80c022092268d5bd6d8401ea88981844fe72a23878f70db76c382d4ddbb9f023d1f1d18c2756a999b69ccb695fc2ca2e71fb3a67768751a1
ssdeep: 384:bqgPnhey7JMBpVrzcstR5IrySFZcAAAAAA0C:bZPheMkXQsP5IryQC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17EB20753DFD41444EAE905B45F67292119EBBB200BBD4ADB2BBC71411B335C2A832F2D
sha3_384: 0895b8cfbb725c697ea185c7fd9b9b90282b312ba9e43f4cecac743b1ad223d53500196784c5aafeb5b91dacecc4ae36
ep_bytes: 558bec6aff682037400068902d400064
timestamp: 2006-03-24 21:51:54

Version Info:

CompanyName: BraveChan Software
FileDescription: BraveChan Software utility
FileVersion: 1, 0, 3, 5
InternalName: BraveChan Software
LegalCopyright: Copyright (C)2014 BraveChan Software
LegalTrademarks: Copyright (C)2014 BraveChan Software
OriginalFilename: chutility.exe
PrivateBuild:
ProductName: BraveChan Software
ProductVersion: 1, 0, 3, 5
Comments: Copyright (C)2014 BraveChan Software
SpecialBuild: No
Translation: 0x0415 0x04b5

Trojan-Downloader.Win32.Upatre.fdx also known as:

BkavW32.Common.C3D3EA0C
LionicTrojan.Win32.Upatre.tpde
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Upatre.Gen.3
FireEyeGeneric.mg.13aff51e4b26cd20
CAT-QuickHealTrojanDwnldr.Upatre.AA4
SkyhighBehavesLike.Win32.Infected.mm
ALYacTrojan.Cutwail.Aj
Cylanceunsafe
ZillyaDownloader.Upatre.Win32.19090
K7AntiVirusTrojan ( 004b6cfa1 )
AlibabaTrojanDownloader:Win32/Upatre.d0043944
K7GWTrojan ( 004b6cfa1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.CC8412991F
VirITTrojan.Win32.Crypt3.CGMP
SymantecMobileInsightAppRisk:Generisk
SymantecDownloader.Upatre
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Upatre.fdx
BitDefenderTrojan.Upatre.Gen.3
NANO-AntivirusTrojan.Win32.Upatre.efguyi
TencentMalware.Win32.Gencirc.13b4db39
TACHYONTrojan-Downloader/W32.Upatre.25600.C
SophosMal/Generic-S
BaiduWin32.Trojan-Downloader.Waski.a
F-SecureTrojan.TR/Kryptik.ZZOA
DrWebTrojan.DownLoader12.31043
VIPRETrojan.Upatre.Gen.3
Trapminemalicious.high.ml.score
EmsisoftTrojan.Upatre.Gen.3 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Upatre.kq
WebrootW32.Trojan.Gen
VaristW32/Trojan.YFDW-7177
AviraTR/Kryptik.ZZOA
Antiy-AVLTrojan[Downloader]/Win32.Upatre
Kingsoftmalware.kb.a.853
XcitiumMalware@#2hohoweecfk3g
ArcabitTrojan.Upatre.Gen.3
ViRobotTrojan.Win32.Agent.25600.DS
ZoneAlarmTrojan-Downloader.Win32.Upatre.fdx
GDataWin32.Trojan.PSE1.QHQVJ
GoogleDetected
AhnLab-V3Trojan/Win32.Upatre.C731523
McAfeeGeneric.vp
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware/Suspicious
RisingTrojan.DL.Win32.Waski.au (CLASSIC)
YandexTrojan.GenAsa!dEK7exoUz+w
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Malware.8127163.susgen
FortinetW32/Kryptik.CZOA!tr
PandaTrj/WLT.B

How to remove Trojan-Downloader.Win32.Upatre.fdx?

Trojan-Downloader.Win32.Upatre.fdx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment