Trojan

Trojan-Downloader.Win32.Upatre.pef removal

Malware Removal

The Trojan-Downloader.Win32.Upatre.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.pef virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan-Downloader.Win32.Upatre.pef?


File Info:

name: 3071BA88EF5C19D27205.mlw
path: /opt/CAPEv2/storage/binaries/bf852e1bb31f1f36ffa6cb5d6e2c9e6cdcdc581461781a317d20d94b07467c87
crc32: 510FCFC0
md5: 3071ba88ef5c19d27205132694e03a36
sha1: 79005635c3bf9462856f0b4b9f711669e2ffb9ba
sha256: bf852e1bb31f1f36ffa6cb5d6e2c9e6cdcdc581461781a317d20d94b07467c87
sha512: bcedf72ee9256f8da0f1c94ace15d3b8f17e4bde0758032c87c0cd97f6897c6dc2b1be6aac0b37ca15f4c6e89a9e7457a0e346854019b7e05b4acbc2dbea4e32
ssdeep: 768:3B8Qv6OepHpKRuviPuvvaVeRMFQMN/o0S:37yTpHpE5wvaVeR0xVo3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159B3F8191AC44237E37BFEB483F75E96E559B17E3C224A2E94DC52088C27F56DB8090E
sha3_384: 6edddb3c1950ad829bf0d6134af98b3e9e2fd76f82b553bafd2887a362eb4ae54e406e4d85afea79e70d462aa81fed36
ep_bytes: ff15e0504000e841000000e8f0ffffff
timestamp: 2004-09-10 05:08:24

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Upatre.pef also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanGen:Variant.Fugrafa.162975
FireEyeGeneric.mg.3071ba88ef5c19d2
CAT-QuickHealTrojan.GenericCS.S22191568
McAfeePWSZbot-FMO!3071BA88EF5C
CylanceUnsafe
ZillyaDownloader.Upatre.Win32.69797
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.8ef5c1
BitDefenderThetaGen:NN.ZexaF.34062.gmX@a8iauHe
CyrenW32/Waski.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Malware.Upatre-9782798-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.pef
BitDefenderGen:Variant.Fugrafa.162975
NANO-AntivirusTrojan.Win32.DownLoad3.cooxrv
AvastWin32:Crypt-QFY [Trj]
TencentMalware.Win32.Gencirc.10ceac5b
Ad-AwareGen:Variant.Fugrafa.162975
SophosML/PE-A
ComodoTrojWare.Win32.Crypt.ZP@83y46r
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Infected.cz
EmsisoftGen:Variant.Fugrafa.162975 (B)
IkarusTrojan-Downloader.Win32.Adload
GDataGen:Variant.Fugrafa.162975
JiangminTrojan.Generic.dzvbp
eGambitUnsafe.AI_Score_55%
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.345EF40
MicrosoftTrojan:Win32/Zbot.SIBG!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/RL.Generic.R246573
Acronissuspicious
VBA32BScope.TrojanDownloader.Agent
MAXmalware (ai score=89)
MalwarebytesTrojan.Upatre.Generic
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingMalware.FakePDF/ICON!1.9C28 (CLASSIC)
YandexTrojan.DL.Waski!XUNiz/ZdPCQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Zbot.HFQ!tr
AVGWin32:Crypt-QFY [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Downloader.Win32.Upatre.pef?

Trojan-Downloader.Win32.Upatre.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment