Trojan

Should I remove “TrojanDownloader:Win32/Upatre!pz”?

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: 7774550065F586CF2275.mlw
path: /opt/CAPEv2/storage/binaries/3b2ebb955f94254d1cced7949f99600db565a168a50338e3b41b66017a258883
crc32: B80D3F59
md5: 7774550065f586cf2275234cb9b2550f
sha1: 24119c922aa6a782c3aeb97a1fe5e5f539c80d0c
sha256: 3b2ebb955f94254d1cced7949f99600db565a168a50338e3b41b66017a258883
sha512: 86aabeb3f2242ccbbc91ebbeb06d4807d4049f7fff2e6b58defa152620caac20415f3ce86678a46a1d0b5d024a680e1038df6d2fbc6080fb64a299a101c4b965
ssdeep: 384:2BXk6zV/N4YzhNAKIs9AedvfNpauhkQ2OzPFt98We:2fNCSAetFpamkQzPFta
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB92FF3C6EDA1AB2D3B7DAB6C6F296C6F925B42374129D0E80CA07450C13F53ADD191E
sha3_384: 4bf8c03aeef9fdebe32364da2d857ec390b8672b4d645d58643e671d8514cdef9d3fb1cb539321e42a571deabac5f9e8
ep_bytes: 60be007040008dbe00a0ffff57eb0b90
timestamp: 2013-11-05 10:07:10

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Shutdowner.lcHq
Elasticmalicious (moderate confidence)
DrWebTrojan.DownLoad4.11213
MicroWorld-eScanDeepScan:Generic.Dacic.7A5D45C8.A.63A5D60E
FireEyeGeneric.mg.7774550065f586cf
SkyhighBehavesLike.Win32.Generic.mt
McAfeeArtemis!7774550065F5
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.SmallGen.Win32.2
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
BitDefenderDeepScan:Generic.Dacic.7A5D45C8.A.63A5D60E
K7GWTrojan-Downloader ( 00457c511 )
Cybereasonmalicious.22aa6a
BitDefenderThetaGen:NN.ZexaF.36792.bmIfaSA1GRgi
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.AAB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Upatre-6803700-0
KasperskyUDS:Trojan.Win32.Generic
AlibabaTrojan:Win32/Upatre.b686
NANO-AntivirusTrojan.Win32.DownLoad3.cmcgoi
ViRobotTrojan.Win32.Upatre.10232[UPX]
RisingDownloader.Waski!1.A489 (CLASSIC)
SophosTroj/Upatre-YW
F-SecureTrojan.TR/Downloader.Gen
BaiduWin32.Trojan-Downloader.Small.ck
VIPREDeepScan:Generic.Dacic.7A5D45C8.A.63A5D60E
EmsisoftDeepScan:Generic.Dacic.7A5D45C8.A.63A5D60E (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.eaiqf
VaristW32/Downloader.OSAR-4665
AviraTR/Downloader.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.b.998
MicrosoftTrojanDownloader:Win32/Upatre!pz
XcitiumTrojWare.Win32.Upatre.A@8qn0ep
ArcabitDeepScan:Generic.Dacic.7A5D45C8.A.63A5D60E
ZoneAlarmUDS:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Upatre.BJ
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Upatre.R258171
Acronissuspicious
VBA32Trojan.Download
ALYacDeepScan:Generic.Dacic.7A5D45C8.A.63A5D60E
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan-Downloader.Win32.Small.16000133
YandexTrojan.GenAsa!BNPu10462mc
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment