Trojan

About “Trojan-Downloader.Win32.Upatre.fxzr” infection

Malware Removal

The Trojan-Downloader.Win32.Upatre.fxzr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.fxzr virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Libya)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan-Downloader.Win32.Upatre.fxzr?


File Info:

name: 94E14A798A4CE618899A.mlw
path: /opt/CAPEv2/storage/binaries/27f68dcdd2d8c280004045d2ec7723967f532127b69fcc5e4ad25ba166ed8d37
crc32: 537DE290
md5: 94e14a798a4ce618899a490a72fb745e
sha1: 304e4d91339d49fa1949f08ae53193c101467d2f
sha256: 27f68dcdd2d8c280004045d2ec7723967f532127b69fcc5e4ad25ba166ed8d37
sha512: 9dcef78ef02f61a4c0b18a2de8f5815b2551334419bec239f5f54ae79c304e0a7213072328b23682e67fa66605893f5a6ba3f44650b35a212c8dbb2b6affc479
ssdeep: 384:Q8u6yN0ZswkNzaMd54PenJHu7GKySeNvtSUx0FJfsom:Q86eiwoZu7idtiaV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194C2D9745EC61BB8F323CEB249F2D69B6635BD61A462030F9050BB314833D729B6DDA4
sha3_384: bc59ecf8c23b8d204d60cb3699fe24d8249daf59fe4596cad261a95f604f5833bf7c0a1a7c8eccb9a69a50c307d9225b
ep_bytes: 60be008040008dbe0090ffff5783cdff
timestamp: 1973-03-04 21:38:58

Version Info:

CompanyName: Landed
FileDescription: Landed company
FileVersion: Version 1.1.16
InternalName: Landed
LegalCopyright: Copyright by Landed
OriginalFilename: Landed
Translation: 0x0408 0x04e3

Trojan-Downloader.Win32.Upatre.fxzr also known as:

BkavW32.AIDetectMalware
AVGWin32:Agent-AULS [Trj]
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Spy.Zbot.FND
FireEyeGeneric.mg.94e14a798a4ce618
CAT-QuickHealTrojanDownloader.Upatre
SkyhighBehavesLike.Win32.Generic.mm
McAfeeArtemis!94E14A798A4C
Cylanceunsafe
ZillyaDownloader.Upatre.Win32.64236
SangforTrojan.Win32.Save.a
AlibabaTrojanDownloader:Win32/Upatre.a96f3985
K7GWTrojan ( 0001140e1 )
K7AntiVirusTrojan ( 0001140e1 )
BaiduWin32.Trojan-Downloader.Waski.a
SymantecDownloader.Upatre!gen5
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Agent.PXO
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Agent-AULS [Trj]
ClamAVWin.Trojan.Ag-1
KasperskyTrojan-Downloader.Win32.Upatre.fxzr
BitDefenderTrojan.Spy.Zbot.FND
NANO-AntivirusTrojan.Win32.MlwGen.dffywr
TencentMalware.Win32.Gencirc.10bfcc3a
EmsisoftTrojan.Spy.Zbot.FND (B)
F-SecureHeuristic.HEUR/AGEN.1314970
DrWebTrojan.Upatre.10623
VIPRETrojan.Spy.Zbot.FND
TrendMicroTROJ_UPATRE.SM37
SophosTroj/HkMain-AZ
Paloaltogeneric.ml
JiangminHoax.ArchSMS.aipg
WebrootTrojan.Dropper.Gen
VaristW32/Upatre.HN.gen!Eldorado
AviraHEUR/AGEN.1314970
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.b.955
MicrosoftTrojanDownloader:Win32/Upatre
XcitiumTrojWare.Win32.TrojanDownloader.Waski.EB@5j320p
ArcabitTrojan.Spy.Zbot.FND
ZoneAlarmTrojan-Downloader.Win32.Upatre.fxzr
GDataWin32.Trojan-Downloader.Upatre.BK
GoogleDetected
AhnLab-V3Downloader/Win.Upatre.R638811
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36804.bmLfa48x!3dG
ALYacTrojan.Spy.Zbot.FND
VBA32TrojanDownloader.Upatre
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!wyngdUsBDpY
IkarusVirTool.Obfuscator
MaxSecureTrojan.Upatre.Gen
FortinetW32/Generic.AC.3E5B91
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Upatre.fswv

How to remove Trojan-Downloader.Win32.Upatre.fxzr?

Trojan-Downloader.Win32.Upatre.fxzr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment