Trojan

TrojanDownloader:Win32/Upatre!pz removal guide

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: 3B54EF5138CFEBA94358.mlw
path: /opt/CAPEv2/storage/binaries/b38e72e1d8ac8723bffd17b556c9d4ec078490a634fcb1931b88c3aa66dc0244
crc32: E345BE98
md5: 3b54ef5138cfeba94358bbc42cc8fbdf
sha1: 5e9c3cf6cd6e3fceea946e91bcb821df44057ea3
sha256: b38e72e1d8ac8723bffd17b556c9d4ec078490a634fcb1931b88c3aa66dc0244
sha512: 99f0131bec44f99aa096acdc3b7bd15dfc8360e7891786179c6f60d1046098377e5072a9b1565a298eb5eb82ac30397df9f423696e2fd2498df40cd62e25be01
ssdeep: 384:5XjtBY918H8Ysx961H0QxeM6bcsu+s+Yp+OLHeNBXREKPfWu/02lRz:ltB01EszS5ejLqerfWk0sRz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142C3503A1ED456B6E3378EB4AAFDB0C5D870BC127AC9840D1499B78508F3F45D9A0E1E
sha3_384: 419b0929582ee53aaa4f7cfd9be911fcf559afd358ef2155c52f6bbab901a3d50cf25606a41e36c6f6a14b492495a97e
ep_bytes: e8330b0000a39e3040006a006a00ff35
timestamp: 2004-09-03 06:08:25

Version Info:

Comments:
CompanyName: MSР« Corp
FileDescrsiption: goС‹.exe
FileVersion: 5.2.1.2
InternalName: go.exe
LegalCopyright: Copyright (C) 2010
LegalTrademarks: Legal
OriginalFilename: gog.exe
PrivateBuild:
ProductName: Goщ
ProductVersion: 5.2.1.3
SpecialBuild:
Translation: 0x0800 0x0026

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
ClamAVWin.Malware.Yarwi-10002303-0
CAT-QuickHealTrojanDownloader.Upatre
SkyhighBehavesLike.Win32.Generic.cz
McAfeeGenericRXIO-IT!3B54EF5138CF
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKD.69124756
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderTrojan.GenericKD.69124756
K7GWTrojan ( 004ebb4c1 )
Cybereasonmalicious.6cd6e3
BitDefenderThetaGen:NN.ZexaF.36792.hm2@ay9Fdtc
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Delf.gen
NANO-AntivirusTrojan.Win32.DownLoad3.fnbrav
MicroWorld-eScanTrojan.GenericKD.69124756
RisingDownloader.Waski!1.A489 (CLASSIC)
SophosTroj/Agent-AEUD
BaiduWin32.Trojan.Kryptik.mp
F-SecureTrojan.TR/Yarwi.AD.5
DrWebTrojan.DownLoad3.28161
ZillyaTrojan.Small.Win32.94469
TrendMicroTROJ_GEN.R03BC0CK823
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3b54ef5138cfeba9
EmsisoftTrojan.GenericKD.69124756 (B)
IkarusTrojan.Win32.Badur
JiangminTrojan/Bublik.hei
WebrootW32.Trojan.Gen
VaristW32/S-856e9e75!Eldorado
AviraTR/Yarwi.AD.5
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.998
MicrosoftTrojanDownloader:Win32/Upatre!pz
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.BP@7j96vd
ArcabitTrojan.Generic.D41EC294
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
ZoneAlarmHEUR:Trojan.Win32.Delf.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R88085
Acronissuspicious
VBA32BScope.Trojan.Delf
ALYacTrojan.GenericKD.69124756
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.18692
TrendMicro-HouseCallTROJ_GEN.R03BC0CK823
TencentTrojan-DL.Win32.Agent.16000354
YandexTrojan.GenAsa!4FxEc4PI3eE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Small.AAB!tr.dldr
AVGWin32:Agent-ASIE [Trj]
AvastWin32:Agent-ASIE [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment