Trojan

How to remove “Trojan:Win32/Upatre!pz”?

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: 082E0038753A581BEAAA.mlw
path: /opt/CAPEv2/storage/binaries/59881570923fa6a60b54e9a1597cf9a30d71ce5665aeac73d69932b3821dc54d
crc32: B7AC7948
md5: 082e0038753a581beaaaa257aa77ce23
sha1: 84055fcc2dc2fc83886188d877177117599898c8
sha256: 59881570923fa6a60b54e9a1597cf9a30d71ce5665aeac73d69932b3821dc54d
sha512: cb3d7d5fd04dca6ad13219723d2a981a48d852407038ee71093eeaa2cad64a5aa7eb03aaafcedc54e2d488889518cc1321ee86fae593cdd2b7c6a82ae17ed513
ssdeep: 6144:PA+AUTpldpbKSBF+A+AUTpldpbKSBF+A+AUTpldpbKSBFD:PA+AUTpldpbKSr+A+AUTpldpbKSr+A+l
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T156248E302FD74AF6E323C9F386FBE7C29579F4719613938ED4880F8545236819960E6A
sha3_384: f0fe12ae91a31b16be3a23b9e9d53809762b2b24578fbc50b9ded44aab22fe0bf5cd495acce2b3cd1de2a8e4ec8cd870
ep_bytes: 5589e581ec3c08000053565731db53ff
timestamp: 2013-10-15 12:38:30

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ppatre.4!c
DrWebmodification of Win32.Virut.56
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.082e0038753a581b
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.dh
McAfeeArtemis!082E0038753A
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 0055f33b1 )
Cybereasonmalicious.c2dc2f
BitDefenderThetaGen:NN.ZexaF.36744.nuZ@aCgBxLoi
VirITTrojan.Win32.Generic.BOHL
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Small.PRL
APEXMalicious
ClamAVWin.Downloader.Upatre-7598844-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.Small.khtugs
AvastWin32:Vitro [Inf]
TencentMalware.Win32.Gencirc.10bf917a
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.Ppatre.Gen.1
TrendMicroTrojan.Win32.UPATRE.SMCBT
Trapminemalicious.moderate.ml.score
SophosMal/EncPk-ACO
IkarusTrojan-Downloader.Win32.Upatre
GDataTrojan.Ppatre.Gen.1
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Trojan.LSRX-1522
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.999
ArcabitTrojan.Ppatre.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Upatre!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacTrojan.Ppatre.Gen.1
MAXmalware (ai score=84)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.UPATRE.SMCBT
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!xjw/xZS1BKE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Dloader.ADC!tr
AVGWin32:Vitro [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment