Trojan

TrojanDownloader:Win32/Upatre!pz information

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: C1870180F5FCBCB244AA.mlw
path: /opt/CAPEv2/storage/binaries/fa0944856b7790f97daba66aeec9016f7b6fa12112a5b8e563b1c20e7c611491
crc32: 167EEABF
md5: c1870180f5fcbcb244aa81ef47267e93
sha1: 38cda4ad04b4b615f9e95fff2fd1ee306b7ede75
sha256: fa0944856b7790f97daba66aeec9016f7b6fa12112a5b8e563b1c20e7c611491
sha512: a5c831b3ec0b33ed31a910943f7dc30692311436feb09378c769244ed887f2f30970f049a1675a48717a0d25bb4863e0f961132d4ff2f603be51a61bcca7bc89
ssdeep: 384:dbnwR2FRnlaeZC1t32L8bG2RbuQb90PGDyaT5jR9Bs7rCSQX:dDwRAnRAGeiPPGDNvtSQX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14253033C6EE91572E37BDAB6D6F691C6B931B0237D02980D40DB43850C13F66EDA1A1E
sha3_384: b943121b6c461b46cedc04ba8725eb7c0635bdd952228db0ba3360b1b63b506f19b5ac2e30c8fbcd9754fcf61247d029
ep_bytes: 558bec81ec3808000053565733f656ff
timestamp: 2013-10-30 10:58:20

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Downloader.JQDW
FireEyeGeneric.mg.c1870180f5fcbcb2
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Dropper.kz
ALYacTrojan.Downloader.JQDW
Cylanceunsafe
VIPRETrojan.Downloader.JQDW
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 0055f33b1 )
Cybereasonmalicious.d04b4b
BaiduWin32.Trojan-Downloader.Small.ck
VirITTrojan.Win32.DownLoad3.BPRD
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.JQDW
NANO-AntivirusTrojan.Win32.DownLoad3.dgmrrz
SUPERAntiSpywareTrojan.Agent/Gen-Waski
AvastWin32:Waski-A [Trj]
SophosTroj/Upatre-YW
F-SecureHeuristic.HEUR/AGEN.1317172
DrWebTrojan.DownLoad3.28161
ZillyaDownloader.SmallGen.Win32.3
TrendMicroTROJ_UPATRE.SMAZ
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Downloader.JQDW (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.azrvz
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1317172
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.996
MicrosoftTrojanDownloader:Win32/Upatre!pz
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.A@52i1eo
ArcabitTrojan.Downloader.JQDW
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Upatre.BJ
VaristW32/S-5aba6b96!Eldorado
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
McAfeeGenericRXUB-BS!C1870180F5FC
VBA32Trojan.Download
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
TencentTrojan-Downloader.Win32.Small.haa
YandexTrojan.DL.Small!9pzVIRFjWnM
IkarusTrojan-Downloader.Win32.Upatre
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.36792.duZ@amDnDEni
AVGWin32:Waski-A [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment