Trojan

About “Trojan:Win32/Upatre!pz” infection

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: 4373154129C3173E68E3.mlw
path: /opt/CAPEv2/storage/binaries/77d835e695891cff1b8ca2f38f8c6c12bbb542dc043b36bfab2d8d98effa34bd
crc32: A20F2F46
md5: 4373154129c3173e68e325e8296deddc
sha1: 730216583809a21aad4ea0d9fa7ee408600e6ce0
sha256: 77d835e695891cff1b8ca2f38f8c6c12bbb542dc043b36bfab2d8d98effa34bd
sha512: 98b09c5566630cedc26dc14fb1d117fd3f0e14529c0751aaca136ecac7f3722e561b40ad8d40fc1ee3dcbc850df33c48807a309d1d1a4880033ff77cf1174c2f
ssdeep: 192:dBRA5onwR2FBAFXiL7w1i8OteV+LI4Ff1iEpFDcbelsG8XXquTFF8IM56+CT478:dtnwR2FBZMtoLIYi40oP8XX/FFE2Tc8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173031B386FD61AB6E377CAF385F296C6A975F432B803D90D80DA07450813F469DA1E1E
sha3_384: daf583fe2cf26905709af7a3cf10fd979bd2eb397a8f7af9da57feeeff4e849e787158c7cb529493607188e538289fac
ep_bytes: 558bec81ec3808000053565733f656ff
timestamp: 2013-10-30 10:58:20

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Downloader.JQDW
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.nz
McAfeeDownloader-FBVZ!4373154129C3
Cylanceunsafe
ZillyaDownloader.SmallGen.Win32.3
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 0055f33b1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Downloader.JQDW
BaiduWin32.Trojan-Downloader.Small.ck
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
ClamAVWin.Downloader.Upatre-10009077-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.JQDW
NANO-AntivirusTrojan.Win32.DownLoad3.dgmrrz
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
RisingDownloader.Agent!1.C06E (CLASSIC)
EmsisoftTrojan.Downloader.JQDW (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Downloader.JQDW
TrendMicroTROJ_UPATRE.SMAZ
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.4373154129c3173e
SophosTroj/Upatre-YW
IkarusTrojan-Downloader.Win32.Upatre
MAXmalware (ai score=87)
JiangminTrojan/Generic.azrvz
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen7
VaristW32/S-654ac031!Eldorado
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.995
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.A@52i1eo
MicrosoftTrojan:Win32/Upatre!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Upatre.BJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.cuY@amDnDEni
DeepInstinctMALICIOUS
VBA32Trojan.Download
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
TencentTrojan-Downloader.Win32.Small.haa
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Waski-A [Trj]
Cybereasonmalicious.83809a
AvastWin32:Waski-A [Trj]

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment