Trojan

Upatre.Trojan.Downloader.DDS removal

Malware Removal

The Upatre.Trojan.Downloader.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Upatre.Trojan.Downloader.DDS virus can do?

  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Upatre.Trojan.Downloader.DDS?


File Info:

crc32: 8721CB01
md5: 1ffc5f131f53235fcd7357cc2e319b38
name: 1FFC5F131F53235FCD7357CC2E319B38.mlw
sha1: 7d381e3c7135402cd489846194ea75c47fe98b14
sha256: 940f308bd20e3c87657891eb3624d182f0597829206afa94fb2e6f3c1ee3fdd7
sha512: d3a66bc2df0c9a3bc0d4633d78c96acf2aeaaeade8a2ddb588ad2f23bebfb899fc71cd9eae7ebd23a12599ebd11142ff8bf5338ff2640aa2d73b578b7ac617a8
ssdeep: 12288:flek7VIjqS/AttnfMznf81aW56jmi4EAEKw46Ye/WOw6iuex082+ueN3RqgW:hfKE8WHEm6Yjjduex082+VNh
type: PE32+ executable (console) x86-64, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Microsoft Corporation. Reservados todos los derechos.
InternalName: dxsetup.exe
FileVersion: 4.9.0.0904
CompanyName: Microsoft Corporation
ProductName: Microsoftxae DirectX para Windowsxae
ProductVersion: 4.9.0.0904
FileDescription: Depuracixf3n del programa de instalacixf3n de Microsoft DirectX
OriginalFilename: dxsetup.exe
Translation: 0x040a 0x04b0

Upatre.Trojan.Downloader.DDS also known as:

Elasticmalicious (high confidence)
DrWebTool.BtcMine.2239
MicroWorld-eScanTrojan.GenericKDZ.65744
FireEyeGeneric.mg.1ffc5f131f53235f
McAfeeGenericRXAA-AA!1FFC5F131F53
MalwarebytesUpatre.Trojan.Downloader.DDS
BitDefenderTrojan.GenericKDZ.65744
Cybereasonmalicious.31f532
SymantecMiner.XMRig
APEXMalicious
AvastWin64:CoinminerX-gen [Trj]
ClamAVWin.Malware.Generickdz-9775964-0
Kasperskynot-a-virus:RiskTool.Win32.BitCoinMiner.ognt
Ad-AwareTrojan.GenericKDZ.65744
SophosTroj/Agent-BCPO
F-SecureHeuristic.HEUR/AGEN.1135765
McAfee-GW-EditionBehavesLike.Win64.CoinMiner.cc
EmsisoftApplication.Generic (A)
JiangminRiskTool.Generic.pkx
AviraHEUR/AGEN.1135765
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojanDownloader:Win32/Upatre
GridinsoftTrojan.Win64.CoinMiner.oa!s2
ArcabitTrojan.Generic.D100D0
ZoneAlarmnot-a-virus:RiskTool.Win32.BitCoinMiner.ognt
GDataTrojan.GenericKDZ.65744
CynetMalicious (score: 100)
AhnLab-V3Malware/Win64.Generic.C4014669
Acronissuspicious
MAXmalware (ai score=81)
ESET-NOD32a variant of Win64/CoinMiner.PQ potentially unwanted
RisingTrojan.Win32/64.XMR-Miner!1.ADCC (TFE:5:cWlFX9xRAN)
YandexTrojan.GenAsa!Xy4KCITNuvE
IkarusTrojan.Win64.CoinMiner
MaxSecureTrojan.Malware.121218.susgen
FortinetW64/CoinMiner.X!tr
AVGWin64:CoinminerX-gen [Trj]

How to remove Upatre.Trojan.Downloader.DDS?

Upatre.Trojan.Downloader.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment