Trojan

How to remove “Trojan-Dropper.Win32.Injector.upzo”?

Malware Removal

The Trojan-Dropper.Win32.Injector.upzo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Injector.upzo virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • NtSetInformationThread: attempt to hide thread from debugger
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Forces a created process to be the child of an unrelated process
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Trojan-Dropper.Win32.Injector.upzo?


File Info:

name: 23B491B45C1D88BB4FA8.mlw
path: /opt/CAPEv2/storage/binaries/8d8b0e6c696cdcb293f163f0acf0336125195cdfbb45e6b42a73f7bdb07d1a2b
crc32: DA46C910
md5: 23b491b45c1d88bb4fa839aa17b06531
sha1: e2370efe7e4109b7c19ec1ee86d3982b30ffd82c
sha256: 8d8b0e6c696cdcb293f163f0acf0336125195cdfbb45e6b42a73f7bdb07d1a2b
sha512: 6254238f28b3b161f70aee7df629884ed25d05641d2f2a4b4801ef05cd129a96c6bbe4b9b0465df3588682987dc99d43f740327544ea69b2c51479cdb7181d90
ssdeep: 24576:lUBH4uWK5gM4ue/s2E5D6wi5jYxfe1uJbw2Q:aHrW9D/g6wQu3JU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FB353356C2E31661D2E606B4DCF3334CFEBB25841C696E2EF394EA8E5F56003B418799
sha3_384: 68aa7ecaa25df9a3de28d4aa3a65405e7eed88231277802bb93b9662bd48d629948360c030174349a60b5e5395ef9c67
ep_bytes: 60e9183effff6639d429fb660fbef8c0
timestamp: 2019-12-22 14:07:13

Version Info:

0: [No Data]

Trojan-Dropper.Win32.Injector.upzo also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43145801
FireEyeGeneric.mg.23b491b45c1d88bb
McAfeeArtemis!23B491B45C1D
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojanDropper:Win32/Injector.2aa7d9ee
Cybereasonmalicious.45c1d8
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Injector.upzo
BitDefenderTrojan.GenericKD.43145801
NANO-AntivirusTrojan.Win32.Inject.hkgtzb
AvastWin32:Malware-gen
TencentWin32.Trojan-dropper.Injector.Hrfg
EmsisoftTrojan.GenericKD.43145801 (B)
ComodoMalware@#3ljubk60860kn
DrWebTrojan.Siggen9.45770
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-S
AviraHEUR/AGEN.1140725
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.306C532
KingsoftWin32.Heur.KVMH017.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan-Dropper.Win32.Injector.upzo
GDataTrojan.GenericKD.43145801
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34182.fHW@aCyzvEbj
ALYacTrojan.GenericKD.43145801
RisingDropper.Injector!8.DC (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.UPZO!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Dropper.Win32.Injector.upzo?

Trojan-Dropper.Win32.Injector.upzo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment