Trojan

Trojan:Win32/Upatre.ME!MTB removal tips

Malware Removal

The Trojan:Win32/Upatre.ME!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre.ME!MTB virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre.ME!MTB?


File Info:

name: 9C6F88C20BD24EA5F60C.mlw
path: /opt/CAPEv2/storage/binaries/c0db1ed422d3f9e785eb076d8fbce43a68eca05f74a5cb0458b4257f8b280c0b
crc32: 524C1D52
md5: 9c6f88c20bd24ea5f60c4596aa8c2992
sha1: 449b899e018deaff3f55d3e3f37bb70524a785bc
sha256: c0db1ed422d3f9e785eb076d8fbce43a68eca05f74a5cb0458b4257f8b280c0b
sha512: 12daab2d26c2a161863715d041492e22dce66af1acb03a246f33ae7b4e1f9768d73c16fd592d1ea13d12f7a35f0a82d2dffc5b754961675dd897176c7cdd603c
ssdeep: 384:xfonwR21BynTRtodBaQpGyY/iLJGSf5lAI+:kwR6aQUtoDROI+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18C03F3386FD60BB2E377CAF785F296D6A935F132B903DA1D80DE0B450813A42AD91D1D
sha3_384: f69c2fb2d542dbc40f64999ccbe8d120e8db9481b5e70669ba648d1b8eca968c46b169ca850ee8c0638b9dae444cbf68
ep_bytes: 558bec81ec3808000053565733f656ff
timestamp: 2014-04-16 07:24:05

Version Info:

0: [No Data]

Trojan:Win32/Upatre.ME!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Gubbins.19
FireEyeGeneric.mg.9c6f88c20bd24ea5
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.nz
McAfeeGenericRXUB-BS!9C6F88C20BD2
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Heur.Mint.Gubbins.19
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 0053eec71 )
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
ArcabitTrojan.Mint.Gubbins.19
BitDefenderThetaGen:NN.ZexaF.36680.cuZ@amVuCIpi
VirITTrojan.Win32.Generic.CGDW
SymantecDownloader.Upatre
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
ClamAVWin.Malware.Upatre-6803700-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Gubbins.19
NANO-AntivirusTrojan.Win32.DownLoad3.dbddjv
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Waski-A [Trj]
SophosTroj/Upatre-YW
BaiduWin32.Trojan-Downloader.Small.ck
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoad3.28161
ZillyaDownloader.Small.Win32.72249
TrendMicroTROJ_UPATRE.SMAZ
EmsisoftGen:Heur.Mint.Gubbins.19 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.azrvz
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/S-cf6c304d!Eldorado
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.AKK@5ixl7u
MicrosoftTrojan:Win32/Upatre.ME!MTB
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Upatre.BJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
VBA32Trojan.Download
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
RisingDownloader.Agent!1.C06E (CLASSIC)
IkarusTrojan-Downloader.Win32.Upatre
FortinetW32/Waski.A!tr
AVGWin32:Waski-A [Trj]
Cybereasonmalicious.e018de
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Upatre.ME!MTB?

Trojan:Win32/Upatre.ME!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment