Malware

Troj/Upatre-ZI removal guide

Malware Removal

The Troj/Upatre-ZI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Upatre-ZI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Upatre-ZI?


File Info:

name: 1A6C7857774A6437A057.mlw
path: /opt/CAPEv2/storage/binaries/e1875691bcd28e20f39e840be2571133259eed9069e0ad046f63212c06021c03
crc32: AC330624
md5: 1a6c7857774a6437a0572b39ab42ae92
sha1: abed89280dace66881434599178cdb008844bd14
sha256: e1875691bcd28e20f39e840be2571133259eed9069e0ad046f63212c06021c03
sha512: d16904cd31bac5fe04edcee68d8ea43d40666004a4232e7eca330097c1874f73cb9cdac38e21e618c489c0555dabe93de8051b5c6dea8eab812f60d8cdbe0c58
ssdeep: 384:D+nSqTQfYjQo7QL/TQfYjQXoHyglpIK0KYVp6QXEVDYpLiq8sSKpE9ego2wQ3Xmy:qSqGCQo7QLGCQYHyYQX8DzNoRQGq5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12AB3B3643BDA5B77E3FB8EB58AF241C6AA71B0117D0AD41D809DC3090863E91DDB1A1F
sha3_384: 6b765afa467dbf2d6eceb72c68477029ddc6e8fe775b415c4eb633855b931bd41ca2a6a668f48fc53e09d0d12a6d7fc5
ep_bytes: e8fb0f00006a006a0268713040006853
timestamp: 2004-10-14 05:48:53

Version Info:

Comments:
CompanyName: MSFT Corp
FileDescrsiption: calc.exe
FileVersion: 2.1.1.2
InternalName: calc.exe
LegalCopyright: Copyright (C) 2011
LegalTrademarks:
OriginalFilename: calc.exe
PrivateBuild:
ProductName: Calc
ProductVersion: 3.1.1.3
SpecialBuild:
Translation: 0x0800 0x0025

Troj/Upatre-ZI also known as:

BkavW32.AIDetectMalware
AVGWin32:CrypterX-gen [Trj]
tehtrisGeneric.Malware
DrWebTrojan.Packed.3036
MicroWorld-eScanTrojan.GenericKDZ.96270
FireEyeGeneric.mg.1a6c7857774a6437
McAfeePWSZbot-FKZ!1A6C7857774A
Cylanceunsafe
ZillyaTrojan.Agent.Win32.2801795
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.7774a6
BitDefenderThetaGen:NN.ZexaF.36196.hm2@a8Dy1Sp
CyrenW32/S-924fb52d!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BNYA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Upatre-9916798-0
KasperskyTrojan.Win32.Agent.ibbb
BitDefenderTrojan.GenericKDZ.96270
NANO-AntivirusTrojan.Win32.Agent.cqjtkw
AvastWin32:CrypterX-gen [Trj]
TencentTrojan.Win32.Agent.pr
EmsisoftTrojan.GenericKDZ.96270 (B)
F-SecureTrojan.TR/Agent.emh
BaiduWin32.Trojan-Downloader.Small.ck
VIPRETrojan.GenericKDZ.96270
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.cz
Trapminemalicious.high.ml.score
SophosTroj/Upatre-ZI
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan.Generic.hicfp
AviraTR/Agent.emh
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Zbot
XcitiumTrojWare.Win32.TrojanDownloader.Agent.BNYA@835oo7
ArcabitTrojan.Generic.D1780E
ZoneAlarmTrojan.Win32.Agent.ibbb
MicrosoftTrojan:Win32/Upatre.MF!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Agent.C5146274
Acronissuspicious
VBA32BScope.Trojan.Yakes
ALYacTrojan.GenericKDZ.96270
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingDownloader.Small!8.B41 (TFE:2:UmKJ3SHWGwB)
YandexTrojan.GenAsa!D2iBtSsGMRU
IkarusTrojan-Downloader.Win32.Small
MaxSecureTrojan.Upatre.Gen
FortinetW32/Zbot.QNYM!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Troj/Upatre-ZI?

Troj/Upatre-ZI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment