Trojan

TrojanDownloader:Win32/Upatre!pz information

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: E580A99A6E429F9AEF91.mlw
path: /opt/CAPEv2/storage/binaries/4bd3202d7b73e8a705bbfd43a60b65e4d43a199d06a5ddc955fe2d3de2bbb774
crc32: B654F8D1
md5: e580a99a6e429f9aef91cc7032f333e2
sha1: 085cf1e65fedf52d3c667d9322b8f7b99434b4c9
sha256: 4bd3202d7b73e8a705bbfd43a60b65e4d43a199d06a5ddc955fe2d3de2bbb774
sha512: c6a59d364604c710d9f89c5eb5b5bcfd7ba73288e34f49952267066ed3a3455eb4963cea3aef21808925b1c1b53262ff3418eb03c622b6734b9f8fcb998afa78
ssdeep: 96:0WVqngpc0njuJ+y2cgi57/zQXGsPrCtvbrJBJug2b0qUfOB+8tugw7kHF+AKM9gn:0s9c0nyIDNEMGKivXObLUy2kzNni
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10F22BF786EE55672E3BB8E7586F661C77579B1627D02C90C10CB87840823B6ADCB0B1F
sha3_384: b8c38282392a5fc7e038a432f8fc2bae5c0a27be9a754711b62602f984606ed70cf6ca15a46e55e40dc6684a93d69d59
ep_bytes: b800604000608da800a0ffff68f6d039
timestamp: 2013-10-15 12:38:30

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Upatre.1j!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
ClamAVWin.Downloader.Upatre-9916228-0
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.zt
McAfeeArtemis!E580A99A6E42
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Waski.Win32.48914
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 005662701 )
AlibabaMalware:Win32/km_24a254.None
K7GWTrojan-Downloader ( 005662701 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Ppatre.Gen.1
BitDefenderThetaAI:Packer.F52CB16E1E
SymantecDownloader.Upatre!gm
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.AL
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad3.cnbuup
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Trojan-gen
RisingVirus.Shodi!1.B830 (CLASSIC)
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader25.56634
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_UPATRE.SM37
SophosTroj/Upatre-YW
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Generic.bclm
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Waski.a
KingsoftWin32.HeurC.KVMH008.a
MicrosoftTrojanDownloader:Win32/Upatre!pz
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
VaristW32/Upatre.LR.gen!Eldorado
AhnLab-V3Trojan/Win32.Upatre.R256307
Acronissuspicious
VBA32Trojan.Generic
TACHYONTrojan-Downloader/W32.Upatre.34218.O
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentTrojan-Downloader.Win32.Waski.16000151
YandexTrojan.Agent!YNhcr1qGsbA
IkarusTrojan-Downloader.Win32.Waski
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.65fedf
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment