Trojan

TrojanDownloader:Win32/Upatre.O removal

Malware Removal

The TrojanDownloader:Win32/Upatre.O is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre.O virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
elwoodcinemas.com
www.hugedomains.com
ocsp.digicert.com
newdirex.com
www.newdirex.com
fanuz.com

How to determine TrojanDownloader:Win32/Upatre.O?


File Info:

crc32: 268A1738
md5: ef7b007b1685a6440bf85158f27eec8d
name: EF7B007B1685A6440BF85158F27EEC8D.mlw
sha1: 240bb545e3529164df1aa0fac98b3029ab44112e
sha256: 1a2dfc45f4cc187da2880fa15c851f564cad4d1ce455a036f8a3313497a5f55b
sha512: 1ffbab5cb4dd1badc82b7633b5d4600f6e579697b4eae0e61f5f3e887d0c669eaa00ae799c60b56738b6b38e71463c68eace7fcb55ee82a5e4a757bbc2877ba6
ssdeep: 192:a4fXYEI3X+rd0fiJY809YkvdVVR38I3qP6sElazyRhDDVC4hhk:P8eKqp0+I3QYlaziDJNk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre.O also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
CynetMalicious (score: 100)
CAT-QuickHealTrojanDownloader.Upatre.A4
ALYacTrojan.Ppatre.Gen.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.b1685a
BaiduWin32.Trojan-Downloader.Waski.a
CyrenW32/A-4051fec9!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
AvastWin32:Agent-AUID [Trj]
ClamAVWin.Trojan.Upatre-6116
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.Bublik.cuxmmn
MicroWorld-eScanTrojan.Ppatre.Gen.1
TencentMalware.Win32.Gencirc.10b85e03
Ad-AwareTrojan.Ppatre.Gen.1
SophosML/PE-A + Mal/Upatre-A
ComodoTrojWare.Win32.Upatre.O@58re0o
BitDefenderThetaGen:NN.ZexaF.34236.amX@aG6EHXc
VIPRETrojan.Win32.Upatre.jr (v)
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionDownloader-FSH!EF7B007B1685
FireEyeGeneric.mg.ef7b007b1685a644
EmsisoftTrojan.Ppatre.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.azrwy
WebrootW32.Trojan.Genkd
AviraTR/Yarwi.AD.113
Antiy-AVLTrojan/Generic.ASMalwS.89909D
MicrosoftTrojanDownloader:Win32/Upatre.O
SUPERAntiSpywareTrojan.Agent/Gen-Simda
GDataTrojan.Ppatre.Gen.1
AhnLab-V3Trojan/Win32.Zbot.R100997
Acronissuspicious
McAfeeDownloader-FSH
MAXmalware (ai score=100)
VBA32Trojan.Bublik
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.Bublik!M2STxHA95b8
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Agent-AUID [Trj]
Paloaltogeneric.ml

How to remove TrojanDownloader:Win32/Upatre.O?

TrojanDownloader:Win32/Upatre.O removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment