Trojan

What is “TrojanDownloader:Win32/Upatre!pz”?

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: D2A4549347AC56D3445D.mlw
path: /opt/CAPEv2/storage/binaries/ea07bc579a518b6914af7ace65d2aa0358f66e32bddfba3f0a85d80ba89c8fd1
crc32: E7859061
md5: d2a4549347ac56d3445df1eaefa18bf6
sha1: 476c523f9c9ac2661e30e4e6dba36a36d96a4882
sha256: ea07bc579a518b6914af7ace65d2aa0358f66e32bddfba3f0a85d80ba89c8fd1
sha512: 15ac171abba6ea8678b2067f8d1e11d240c0e1935bccb1e0dcd03f167a908696cf447fcf9b361eac7cbf6ad6aa893eb78f75bc9b17b393d0d896780033e782eb
ssdeep: 384:Xz8qWI9TtGINz8PU7s4kAPHCr6tps5jOPPLNK:XYqTTIINYPmTPltp1PPxK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11A92043C5ED51572E3B7CABAC6F655C7B974B4223D129CCD40CA43840C23B66EDA1A2D
sha3_384: 008e3f74a2f851c0ecd8508091db027d6b36c772bc708c2183fb14381ff1db8a33ba278c40611365490e443c8368c749
ep_bytes: b800624000ffe088f8a8d46994d9b7f5
timestamp: 2013-09-11 14:39:41

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
ClamAVWin.Malware.Ppatre-7113132-0
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXIH-XP!D2A4549347AC
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Generic.Win32.8667
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005568151 )
BitDefenderTrojan.Ppatre.Gen.1
K7GWTrojan ( 005568151 )
Cybereasonmalicious.f9c9ac
BitDefenderThetaAI:Packer.5516F9F41E
SymantecDownloader.Upatre!gm
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Small.PRL
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan-Downloader.Win32.Waski.gen
AlibabaTrojanDownloader:Win32/Upatre.f6c1fc82
RisingTrojan.Kryptik!1.BB30 (CLASSIC)
SophosW32/Systro-AB
F-SecureTrojan.TR/Dldr.Small.jnlaf
DrWebTrojan.DownLoader26.64201
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_UPATRE.SMAS
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d2a4549347ac56d3
EmsisoftTrojan.Ppatre.Gen.1 (B)
IkarusTrojan-Downloader.Win32.Small
JiangminTrojan.Generic.dunym
GoogleDetected
AviraTR/Dldr.Small.jnlaf
Antiy-AVLTrojan[Downloader]/Win32.Upatre
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Upatre!pz
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.ACC@56yhj8
ArcabitTrojan.Ppatre.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Upatre.BJ
VaristW32/S-c0caa7f2!Eldorado
AhnLab-V3Trojan/Win32.Upatre.R289382
Acronissuspicious
VBA32Trojan.Downloader
ALYacTrojan.Ppatre.Gen.1
MAXmalware (ai score=87)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAS
TencentTrojan-DL.Win32.Upatre.kaj
YandexTrojan.GenAsa!LXiB97J6ZtU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Parite.C
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment