Trojan

How to remove “Trojan:Win32/Upatre!pz”?

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: C84DEBDBBE1F24F6ADB2.mlw
path: /opt/CAPEv2/storage/binaries/93f1b2d86d4c56e220b14097190385f9bf983d3ed347f298deb8686b67a73d4c
crc32: AE014C2C
md5: c84debdbbe1f24f6adb2b823c5b8ed94
sha1: 306238bb3a4d78ce14b3a88005d00e05d2e4373b
sha256: 93f1b2d86d4c56e220b14097190385f9bf983d3ed347f298deb8686b67a73d4c
sha512: 2f4a42638b658d01854bd3abd0b8ec8bdbe0978e54dbb31fa65c2f034e6719aff453471db4a87e82a2a0d0e427624d79235be23a1f0b849b1f523ecae36f863f
ssdeep: 192:F4VbbMn3jTenK/47kFp5m0DeZaT0KY15NcLsDe/UAj5CV5:Bn3yK/444daQ15NcQDsUq5C7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18142103C6ED62AB7E77BCAB6C5F205C7FA65B41239025C0E508703450823F97BD9161E
sha3_384: f71d208566a29852fc4e479bbfeee65e507dba9295a031577e4c4855dcb6e305e4e82397ac38f7e827a01419258ba98e
ep_bytes: 8bec81c4f4feffffe8000000005b6681
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ppatre.b!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.c84debdbbe1f24f6
SkyhighBehavesLike.Win32.Downloader.lt
ALYacTrojan.Ppatre.Gen.1
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Upatre.1485542b
K7GWTrojan ( 005aede11 )
K7AntiVirusTrojan ( 005aede11 )
BitDefenderThetaAI:Packer.2F53BD471E
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Tiny.NKP
APEXMalicious
ClamAVWin.Downloader.Upatre-10009298-0
KasperskyHEUR:Trojan-Dropper.Win32.Dapato.vho
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.Upatre.denomc
AvastWin32:Trojan-gen
RisingDownloader.Waski!1.E076 (CLASSIC)
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoad3.33795
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_GEN.R002C0DA824
Trapminesuspicious.low.ml.score
SophosMal/Upatre-AS
IkarusTrojan-Downloader.Win32.Tiny
MAXmalware (ai score=87)
GDataTrojan.Ppatre.Gen.1
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Tiny.L.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.AGeneric
Kingsoftmalware.kb.a.1000
ArcabitTrojan.Ppatre.Gen.1
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dapato.vho
MicrosoftTrojan:Win32/Upatre!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Gen
Acronissuspicious
McAfeeGenericATG-FABE!C84DEBDBBE1F
TACHYONTrojan-Dropper/W32.Dapato.12638
VBA32BScope.TrojanDownloader.Upatre
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DA824
TencentTrojan-Dropper.Win32.Dapato.ka
YandexTrojan.DL.Tiny!9tgbM9f/Vic
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.C!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment