Trojan

TrojanDownloader:Win32/Upatre.L removal instruction

Malware Removal

The TrojanDownloader:Win32/Upatre.L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre.L virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Upatre.L?


File Info:

crc32: 4E6D0723
md5: be584064a3de595373fd4dc680beeb8c
name: BE584064A3DE595373FD4DC680BEEB8C.mlw
sha1: ebc94425a8653a08d23afd94868afb7f67c44f2f
sha256: 211d054646a82385cf02d5b1e03bede18e59450faab001c51d37548090e8a97a
sha512: 6aea6a9dfdd6c6f83beff825dd5f04b59a4b32052591d2123408121219d3cd5a05c03f5640282837c200bf8d3eff3f72c8fc1e3af2d500d97eb0b196942e6c51
ssdeep: 384:6VulHhduwCgY8cjA5wwCC0gDqIoxO+PLWoEWyUZ:bhdCjewAfV+POs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre.L also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0050357f1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.31502
MicroWorld-eScanTrojan.GenericKD.1508695
CAT-QuickHealTrojanDownloader.Upatre.A4
ALYacTrojan.GenericKD.1508695
CylanceUnsafe
ZillyaTrojan.Bublik.Win32.12900
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0050357f1 )
Cybereasonmalicious.4a3de5
BaiduWin32.Trojan-Downloader.Waski.a
CyrenW32/Trojan.MINN-2770
SymantecDownloader.Upatre
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
AvastWin32:Agent-AUID [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.1508695
NANO-AntivirusTrojan.Win32.DownLoad3.csqxvw
TencentMalware.Win32.Gencirc.10b8ae39
Ad-AwareTrojan.GenericKD.1508695
SophosML/PE-A + Troj/Mdrop-FRT
ComodoTrojWare.Win32.Yarwi.BV@56uh49
BitDefenderThetaGen:NN.ZexaF.34294.amX@aqI31abi
VIPRETrojan.Win32.Upatre.jr (v)
TrendMicroTROJ_UPATRE.SMBX
McAfee-GW-EditionBehavesLike.Win32.Downloader.lm
FireEyeGeneric.mg.be584064a3de5953
EmsisoftTrojan.GenericKD.1508695 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Agent.emov
Webroot
AviraTR/Spy.Zbot.rgoza.6
Antiy-AVLTrojan/Generic.ASMalwS.77A2B3
KingsoftHeur.SSC.2782274.0010.(kcloud)
MicrosoftTrojanDownloader:Win32/Upatre.L
SUPERAntiSpywareTrojan.Agent/Gen-Waski
GDataTrojan.GenericKD.1508695
AhnLab-V3Trojan/Win32.Waski.C252209
Acronissuspicious
McAfeeDownloader-FGQ!BE584064A3DE
MAXmalware (ai score=99)
VBA32Trojan.Bublik
MalwarebytesTrojan.Email.FakeDoc
PandaGeneric Malware
TrendMicro-HouseCallTROJ_UPATRE.SMBX
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.Bublik!uOJIZsEaNik
IkarusTrojan-Downloader.Win32.Upatre
FortinetW32/Waski.A!tr
AVGWin32:Agent-AUID [Trj]
Paloaltogeneric.ml

How to remove TrojanDownloader:Win32/Upatre.L?

TrojanDownloader:Win32/Upatre.L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment