Trojan

How to remove “TrojanDownloader:Win32/Upatre!pz”?

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Detects Joe or Anubis Sandboxes through the presence of a file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: B0892552FC254FE62F90.mlw
path: /opt/CAPEv2/storage/binaries/2f77d1aada5facef3b3e63a32615a94a04c7595fab578a443b5aa6bfce0528ca
crc32: B2AC8432
md5: b0892552fc254fe62f90701f5f4fad7f
sha1: d48bd9e712b714d410fee81681f09c502424bd13
sha256: 2f77d1aada5facef3b3e63a32615a94a04c7595fab578a443b5aa6bfce0528ca
sha512: 53da376bd773df5fefc4668d99344290a35673f1f6d54f249175c74b0a4836309354ad5545bc2c73a630020508fdd05cd71291c86ef9a6f9f0262ee277257e5b
ssdeep: 768:75wRI7PsED3VK2+ZtyOjgO4r9vFAg2rqrINT0qxn0GVkpkY/67G2qSfv:+wYTjipvF2N0qxdkpkweG2qSX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB331C387AD155B2E3BB867684F241D6A931BC627D51891FB4CA334D0833F62EC91E1E
sha3_384: aa1e5138ce5ffaedb6e9648b4ea08e4c31509cdad75876696695e4d670861aecf69c9df543103477d6edb8f0c8779c03
ep_bytes: 558bec81ec3c04000053565733f656ff
timestamp: 2013-08-29 14:03:58

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanTrojan.Ppatre.Gen.1
ClamAVWin.Downloader.Upatre-10018147-0
FireEyeGeneric.mg.b0892552fc254fe6
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.qt
McAfeeDownloader-FBVZ!B0892552FC25
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Generic.Win32.125166
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0048f6391 )
K7GWTrojan-Downloader ( 0048f6391 )
Cybereasonmalicious.712b71
BitDefenderThetaGen:NN.ZexaF.36744.duZ@amzDlEfi
VirITTrojan.Win32.Generic.BLHT
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad3.emvztu
AvastWin32:Downloader-WID [Trj]
TencentTrojan.Win32.Downloader.wb
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureHeuristic.HEUR/AGEN.1317172
BaiduWin32.Trojan-Downloader.Waski.k
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_UPATRE.SMAZ
Trapminesuspicious.low.ml.score
SophosTroj/Upatre-YW
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojanDownloader.Generic.akum
GoogleDetected
AviraHEUR/AGEN.1317172
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.998
XcitiumTrojWare.Win32.TrojanDownloader.Small.CDC@8mzsfr
ArcabitTrojan.Ppatre.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDownloader:Win32/Upatre!pz
VaristW32/S-dd480c14!Eldorado
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
VBA32Trojan.Download
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.Agent!ySITDsmlrks
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Dloader.ADC!tr
AVGWin32:Downloader-WID [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment