Malware

Troj/Upatre-YZ removal

Malware Removal

The Troj/Upatre-YZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Upatre-YZ virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Troj/Upatre-YZ?


File Info:

name: 4FB0EC839049A43ECD96.mlw
path: /opt/CAPEv2/storage/binaries/b6854bf32d14cee7db26b452f102ebddb117b1de0433f0773c04b4c31a8dd3ad
crc32: 7B43DD63
md5: 4fb0ec839049a43ecd96f1c69a9d1e04
sha1: 15a11224429ee308165ecb2c336d0badc857af09
sha256: b6854bf32d14cee7db26b452f102ebddb117b1de0433f0773c04b4c31a8dd3ad
sha512: 5227ffa0c88ac060104392b6c0266decfbfa420a7f8120e02fc914b6f52205cd1237a04642be9bbb449227b111e1611b2944b8105b1eebe45067bd3d42bdf2d0
ssdeep: 384:OG4TebV6dbuoh1kX681FN6BAZAHh6yCqXKKC:Ieb0brB81FQ/Hh6J
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FC2143C6ED55A72E37BCAB6C5F651C7F921B5233C02980D40DA47850813FA6EDE261E
sha3_384: 393ce8b5841a631025da41f3dcde4a0931524828dd7f1c9978cbf772e178b9af4d44ed99a5ed5a14a87367ee9d0cef3c
ep_bytes: eb03c20c00558bec81ec00100000b800
timestamp: 2013-10-15 12:38:30

Version Info:

0: [No Data]

Troj/Upatre-YZ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Upatre.tomf
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.4fb0ec839049a43e
ALYacTrojan.Ppatre.Gen.1
MalwarebytesWaski.Trojan.Downloader.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0048f6391 )
AlibabaTrojan:Win32/Agent.e055
K7GWTrojan-Downloader ( 0048f6391 )
Cybereasonmalicious.39049a
BitDefenderThetaAI:Packer.E19F0F6D1D
VirITTrojan.Win32.Dnldr25.DFUG
CyrenW32/S-dc952d46!Eldorado
SymantecDownloader.Upatre!gm
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Malware.Upatre-9800774-1
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Ppatre.Gen.1
AvastWin32:Evo-gen [Trj]
TencentTrojan-Downloader.Win32.Waski.wa
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureTrojan.TR/Dldr.Waski.wmfdt
DrWebTrojan.DownLoader25.56634
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_GEN.R002C0DEP23
McAfee-GW-EditionBehavesLike.Win32.Generic.mt
Trapminemalicious.moderate.ml.score
SophosTroj/Upatre-YZ
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan.Generic.auets
GoogleDetected
AviraTR/Dldr.Waski.wmfdt
Antiy-AVLGrayWare/Win32.BlackMoon.b
XcitiumTrojWare.Win32.Flooder.Agent.NAS@74ax2y
ArcabitTrojan.Ppatre.Gen.1
ViRobotTrojan.Win.Z.Upatre.26148.R
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
MicrosoftTrojan:Win32/SmokeLoader.FT!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1860072
Acronissuspicious
McAfeeGenericRXAA-FA!4FB0EC839049
MAXmalware (ai score=88)
VBA32BScope.Trojan.Meterpreter
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEP23
RisingTrojan.Agent!1.A4D8 (CLASSIC)
IkarusTrojan.Win32.VB
FortinetW32/Agent.NAZ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/Upatre-YZ?

Troj/Upatre-YZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment