Trojan

UDS:Trojan.Win32.Bublik removal tips

Malware Removal

The UDS:Trojan.Win32.Bublik is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan.Win32.Bublik virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine UDS:Trojan.Win32.Bublik?


File Info:

name: D48A605E76852E62341F.mlw
path: /opt/CAPEv2/storage/binaries/ee24e2052c2b70bf4bbfc5691f81dca8decc2671fc0a813b15e7a01afa4aca20
crc32: EA4D7F14
md5: d48a605e76852e62341f23675b2157d8
sha1: bd0c09b4c399c22c28511197f0c502efd88067b2
sha256: ee24e2052c2b70bf4bbfc5691f81dca8decc2671fc0a813b15e7a01afa4aca20
sha512: e0a7f5f21ebe77a398d3fff905d6d093f645933d3a73ec31c1eb40cf542fbe7f544d2c423e4f560cfed35b179fb9109b8d90cb85874f49cbf745df3bbcb7f16e
ssdeep: 192:nZcI7Ylt2OOZ98D3fLPeAxEzPI+EJj/2XY81MMlY:nikmHcGbeUc++Xh1MMm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0E22DD7F7D05904E66A5A3081F39A1714A2BCFC3E73A10F298973922E738D1AB54EC1
sha3_384: f73d59dce1568d8637c4407ebd4107332bedd1632b7bcf08c8cf3c349609a2bb1ed6f6d9fe1539375d7324447f31fa21
ep_bytes: 558bec83c4d48d4dd851ff1524304000
timestamp: 2002-04-27 03:58:53

Version Info:

0: [No Data]

UDS:Trojan.Win32.Bublik also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Upatre.Gen.3
FireEyeGeneric.mg.d48a605e76852e62
CAT-QuickHealTrojanDownloader.Upatre.V4
ALYacTrojan.Upatre.Gen.3
CylanceUnsafe
ZillyaTrojan.Bublik.Win32.26797
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.Upatre.Gen.3
K7GWTrojan-Downloader ( 0048f6391 )
K7AntiVirusTrojan-Downloader ( 0048f6391 )
ArcabitTrojan.Upatre.Gen.3
BitDefenderThetaGen:NN.ZexaF.34062.cq1@aOdRwbhi
CyrenW32/Trojan.NKRL-2285
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.A
BaiduWin32.Trojan-Downloader.Waski.a
TrendMicro-HouseCallTROJ_UPATRE.SM37
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Bublik
AlibabaMalware:Win32/km_24340.None
NANO-AntivirusTrojan.Win32.Zbot.cxtvcv
ViRobotTrojan.Win32.Zbot.17920.A
RisingTrojan.DL.Win32.Upatre.aab (CLASSIC)
Ad-AwareTrojan.Upatre.Gen.3
SophosML/PE-A + Mal/Zbot-QL
ComodoTrojWare.Win32.Kryptik.CBXB@5a837k
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Win32.Upatre.ab (v)
TrendMicroTROJ_UPATRE.SM37
EmsisoftTrojan.Upatre.Gen.3 (B)
APEXMalicious
JiangminTrojanSpy.Zbot.eegg
MaxSecureTrojan.Upatre.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.9EFCEF
GridinsoftRansom.Win32.Zbot.sa
MicrosoftTrojanDownloader:Win32/Upatre
GDataTrojan.Upatre.Gen.3
SentinelOneStatic AI – Malicious PE
AhnLab-V3Dropper/Win32.Zbot.R106661
Acronissuspicious
McAfeeUpatre-FAAG!D48A605E7685
VBA32Trojan.Zbot.1254
MalwarebytesMalware.AI.3412300828
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10cf9005
YandexTrojan.DL.Upatre!HwavJJ8UVWQ
MAXmalware (ai score=82)
FortinetW32/Kryptik.GQIX!tr
AVGWin32:Dropper-NWS [Trj]
Cybereasonmalicious.e76852
AvastWin32:Dropper-NWS [Trj]

How to remove UDS:Trojan.Win32.Bublik?

UDS:Trojan.Win32.Bublik removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment