Trojan

TrojanDownloader:Win32/Upatre!pz removal guide

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: 8ABEA8F479ED8B41FEBB.mlw
path: /opt/CAPEv2/storage/binaries/3635b9cfd48baf3fb978ad65e98e3e9856fcaaf8f1ff48a4ff7d92b1989b9c4b
crc32: A438D14B
md5: 8abea8f479ed8b41febb990b62360296
sha1: 14276aa4153d02ad9c126feb26cacdccc9963990
sha256: 3635b9cfd48baf3fb978ad65e98e3e9856fcaaf8f1ff48a4ff7d92b1989b9c4b
sha512: 29c7c98abeebdf04bf1c63c75f6e8b2225973669f79633dee4322fd7e97ab73715fbb14d6a8fb71d13a11237476e9a25dbdb0d80347572a68ee889876985d36d
ssdeep: 768:dwowR6XaUVlYNPxkfLsApVZRP+4xGXhda1TI:dwlALPYNqXFULay
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16F33123C6EE81672D3B7DAB6D6F695C6BD35B4237902980D40DA03840C23F56EDA1B1E
sha3_384: ddd22e3cb965e98a4855962f9bba4001f13fda0c211f6c612699b6b8251f29987a614a96fe38cdc6461fa726fefd2cf6
ep_bytes: 558bec81ec3808000053565733f656ff
timestamp: 2013-10-30 10:58:20

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lY5V
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.69180513
ClamAVWin.Downloader.Upatre-10009077-0
FireEyeGeneric.mg.8abea8f479ed8b41
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.pz
ALYacTrojan.GenericKD.69180513
Cylanceunsafe
ZillyaDownloader.SmallGen.Win32.3
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
AlibabaTrojan:Win32/Upatre.b686
K7GWTrojan-Downloader ( 0055f33b1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D41F9C61
BitDefenderThetaGen:NN.ZexaF.36792.duY@amDnDEni
VirITTrojan.Win32.DownLoad3.BPRD
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.GenericKD.69180513
NANO-AntivirusTrojan.Win32.DownLoad3.dgmrrz
SUPERAntiSpywareTrojan.Agent/Gen-Waski
AvastWin32:Waski-A [Trj]
TencentTrojan-Downloader.Win32.Small.haa
EmsisoftTrojan.GenericKD.69180513 (B)
BaiduWin32.Trojan-Downloader.Small.ck
F-SecureHeuristic.HEUR/AGEN.1317172
DrWebTrojan.DownLoad3.28161
VIPRETrojan.GenericKD.69180513
TrendMicroTROJ_UPATRE.SMAZ
Trapminemalicious.moderate.ml.score
SophosTroj/Upatre-YW
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.azrvz
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1317172
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.995
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.A@52i1eo
MicrosoftTrojanDownloader:Win32/Upatre!pz
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
VaristW32/S-5aba6b96!Eldorado
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
McAfeeDownloader-FBVZ!8ABEA8F479ED
MAXmalware (ai score=86)
VBA32Trojan.Download
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
RisingDownloader.Agent!1.C06E (CLASSIC)
YandexTrojan.GenAsa!xjw/xZS1BKE
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Waski-A [Trj]
Cybereasonmalicious.4153d0
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment