Trojan

TrojanDownloader:Win32/Upatre!pz malicious file

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: 0063A83619C73BCA9633.mlw
path: /opt/CAPEv2/storage/binaries/afeb14056671b013bbc5f2316c37b7f7383d6706e6e285bb324196b52dbfd5ab
crc32: F8B274FC
md5: 0063a83619c73bca96332b83e979af22
sha1: 5c384786909b6e979ca0c7eb8ea9282b16ee5d62
sha256: afeb14056671b013bbc5f2316c37b7f7383d6706e6e285bb324196b52dbfd5ab
sha512: 6a497464b0f0ab01b54ea73b68ea773cf1c6acff05f6c441172a8aeebe70e3201946bac5509f1b7344d3dbc3a9e0e9ed700cf505d8f4994a3ec7b578dff45a7b
ssdeep: 192:0s9c0nyIDNEMGKivXObLUy2kzNnTRDek1/p8T:zPDNExKMebFJzhH1x8T
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188329E785EE55672E3BB8E76C6F661C7B579B1623D028C0D10CB47840823B66DCB1A1E
sha3_384: cfac468d33653ac21b362d65f097d2d2ca4d0bf16e5ac2d73ec9a51433e76c87b4ba89c0daa67f01abd4341dce715023
ep_bytes: b800604000608da800a0ffff68f6d039
timestamp: 2013-10-15 12:38:30

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Upatre.1j!c
Elasticmalicious (high confidence)
ClamAVWin.Downloader.Upatre-9916228-0
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.lt
ALYacTrojan.Ppatre.Gen.1
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Ppatre.Gen.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 005662701 )
BitDefenderTrojan.Ppatre.Gen.1
K7GWTrojan-Downloader ( 005662701 )
Cybereasonmalicious.6909b6
SymantecDownloader.Upatre!gm
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.AL
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.pef
AlibabaMalware:Win32/km_24a254.None
NANO-AntivirusTrojan.Win32.DownLoad3.cnbuup
MicroWorld-eScanTrojan.Ppatre.Gen.1
AvastWin32:Trojan-gen
RisingVirus.Shodi!1.B830 (CLASSIC)
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader25.56634
ZillyaDownloader.Waski.Win32.48914
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.0063a83619c73bca
SophosTroj/Upatre-YW
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Generic.bclm
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.999
MicrosoftTrojanDownloader:Win32/Upatre!pz
ArcabitTrojan.Ppatre.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.pef
GDataWin32.Trojan-Downloader.Upatre.BJ
VaristW32/Upatre.LR.gen!Eldorado
AhnLab-V3Trojan/Win32.Upatre.R256307
Acronissuspicious
McAfeeArtemis!0063A83619C7
TACHYONTrojan-Downloader/W32.Upatre.36148.J
VBA32Trojan.Generic
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentTrojan-Downloader.Win32.Waski.16000151
YandexTrojan.Agent!YNhcr1qGsbA
IkarusTrojan-Downloader.Win32.Waski
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
BitDefenderThetaAI:Packer.F52CB16E1E
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment