Trojan

TrojanDownloader:Win32/Upatre!pz removal

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: 9736D33957EFA9B6DFB5.mlw
path: /opt/CAPEv2/storage/binaries/21e306cbed5da86f4aeb75e0cfbd8ee46cce477740b05d76363da17e5629156a
crc32: CED4FF11
md5: 9736d33957efa9b6dfb53907ba54b9d3
sha1: 246e97a98a30ec94f1f65cb96ea561c94eb93f07
sha256: 21e306cbed5da86f4aeb75e0cfbd8ee46cce477740b05d76363da17e5629156a
sha512: 86b1a4f44b4f52380b1d7912956d9d849c24db74b6237c82c65e4e287347e1b88b18ddc04ece1d81822c6e0239dd20fbac650c6a5c231942b29b9bcc2439384e
ssdeep: 192:dBRA5onwR2FBAFXiL7w1i8OteVCajC6NefM3sxbxcxrn/SdD7RbeXVd78IB:dtnwR2FBZMt9rgzctGar
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CD0316342FEA1AB5E377DAF396F2D2C5A975F032B807D60D90DA0B450813A45DDA0E1E
sha3_384: 2eeea01de1a839f5bd55532ffeac8104aedfb3bbd6e2efc824185de41288a6d740d8e515ea1a3b74a6c90087fc81ffa7
ep_bytes: 558bec81ec3808000053565733f656ff
timestamp: 2013-10-30 10:58:20

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lY5V
tehtrisGeneric.Malware
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.pz
McAfeeDownloader-FBVZ!9736D33957EF
Cylanceunsafe
VIPRETrojan.Downloader.JQDW
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Upatre.b686
K7GWTrojan-Downloader ( 0055f33b1 )
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
ArcabitTrojan.Downloader.JQDW
BaiduWin32.Trojan-Downloader.Small.ck
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
ClamAVWin.Downloader.Upatre-10009077-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Downloader.JQDW
NANO-AntivirusTrojan.Win32.DownLoad3.dgmrrz
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
MicroWorld-eScanTrojan.Downloader.JQDW
AvastWin32:Waski-A [Trj]
TencentTrojan-Downloader.Win32.Small.haa
EmsisoftTrojan.Downloader.JQDW (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.DownLoad3.28161
ZillyaDownloader.SmallGen.Win32.3
TrendMicroTROJ_UPATRE.SMAZ
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.9736d33957efa9b6
SophosTroj/Upatre-YW
IkarusTrojan-Downloader.Win32.Upatre
JiangminTrojan/Generic.azrvz
WebrootW32.Trojan.Gen
VaristW32/S-654ac031!Eldorado
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.995
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.A@52i1eo
MicrosoftTrojanDownloader:Win32/Upatre!pz
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
GoogleDetected
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36792.cuY@amDnDEni
ALYacTrojan.Downloader.JQDW
MAXmalware (ai score=83)
VBA32Trojan.Download
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
RisingDownloader.Agent!1.C06E (CLASSIC)
YandexTrojan.GenAsa!xjw/xZS1BKE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Waski-A [Trj]
Cybereasonmalicious.98a30e
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment