Trojan

TrojanDownloader:Win32/Upatre!pz removal tips

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: 60BE62812D9F30B0D8C0.mlw
path: /opt/CAPEv2/storage/binaries/76b61097bad449b2f89e6a06db273c5a2ff6da0e9b4e0eb40f8d0425cf664848
crc32: F7D3D61B
md5: 60be62812d9f30b0d8c0194069fa3dbf
sha1: 3384cb335306bfd17b6d4d06ce05fded1895b8a4
sha256: 76b61097bad449b2f89e6a06db273c5a2ff6da0e9b4e0eb40f8d0425cf664848
sha512: 3f83e3f03db6d503f2924634de95d2ed069baa23264b4b866ecfb87425732382a9c9c08a2db8bcd7b90711be95a9e4aba2a1d98e2ff953366ecd5abbf0ca1ec7
ssdeep: 384:Xz8qWI9TtGINz8PUAZL5G2WdLxSiPuCxvCDoCFJCpIs1DZ:XYqTTIINYPJZLOdLxxWCJ2oCFJf0DZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17E92203C5ED51AB2E377CAB6CAF245C7B965B42239129CCE40CB43850813F57BDA1A1E
sha3_384: 9265b29c85413cae9326adb8a0883f9dc4b8284026799a58aa97ba46ec7294da5cccfd5c92c6a291f22b2c9b55e11833
ep_bytes: b800624000ffe088f8a8d46994d9b7f5
timestamp: 2013-09-11 14:39:41

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.71273870
FireEyeGeneric.mg.60be62812d9f30b0
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.lt
McAfeeGenericRXIH-XP!60BE62812D9F
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Generic.Win32.8667
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005568151 )
K7GWTrojan ( 005568151 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.5516F9F41E
SymantecDownloader.Upatre!gm
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Small.PRL
APEXMalicious
ClamAVWin.Malware.Ppatre-7113132-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.71273870
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-DL.Win32.Upatre.kaj
SophosW32/Systro-AB
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader26.64201
VIPRETrojan.GenericKD.71273870
TrendMicroTROJ_UPATRE.SMAS
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.71273870 (B)
IkarusTrojan-Downloader.Win32.Small
GDataWin32.Trojan.PSE.H9T46E
JiangminTrojan.Generic.dunym
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/S-c0caa7f2!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Upatre
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.ACC@56yhj8
ArcabitTrojan.Generic.D43F8D8E
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDownloader:Win32/Upatre!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R289382
Acronissuspicious
VBA32Trojan.Downloader
ALYacTrojan.GenericKD.71273870
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAS
RisingTrojan.Kryptik!1.BB30 (CLASSIC)
YandexTrojan.GenAsa!LXiB97J6ZtU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Parite.C
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.35306b
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment