Trojan

What is “Trojan:Win32/Upatre!pz”?

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: 77D081E2A16C7895E6CB.mlw
path: /opt/CAPEv2/storage/binaries/2f02961480e5946b2be0640cf529741273ce5fa7f4111da126338ab8b08b7ae3
crc32: E9640BEB
md5: 77d081e2a16c7895e6cbee2dc9fa9255
sha1: 111f9bda79423c974465c033a5d46f50b0b2f52a
sha256: 2f02961480e5946b2be0640cf529741273ce5fa7f4111da126338ab8b08b7ae3
sha512: 2858c45c040a675b6a86671db501d8f273e233207d6bc1e1292f1dd7b5bc74d4a263b3e1648ceef9db04e2b17e03c3285ffcc08beb6d40cec5028366f075e0af
ssdeep: 192:F4VbbMn3junK/47/HoF+/FD2SZwvYPZZdIAdHhwC+nKz123vGrhD:Bn3OK/4TIF+/EdvyZzfdBwCkgYU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A42453C6ED52AB7E37BCAB689F255CBF965B0123A025D0D408703840C23F97ADE165E
sha3_384: d0955b0207f8865bd9eb87656f080084c0714525245a12cfe2a421e23bcac295d6aaab6818cb92d91b8c2928195c9a87
ep_bytes: 8bec81c4f4feffffe8000000005b6681
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Upatre.1j!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
ClamAVWin.Downloader.Upatre-9976824-0
FireEyeGeneric.mg.77d081e2a16c7895
SkyhighBehavesLike.Win32.Downloader.lt
McAfeeGenericATG-FABE!77D081E2A16C
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Upatre.b03f274c
K7GWTrojan ( 005aede11 )
K7AntiVirusTrojan ( 005aede11 )
ArcabitTrojan.Ppatre.Gen.1
BitDefenderThetaAI:Packer.3828A9041E
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Tiny.NKP
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Dropper.Win32.Dapato.vho
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.Upatre.denomc
AvastWin32:Trojan-gen
RisingDownloader.Waski!1.E076 (CLASSIC)
SophosMal/Upatre-AS
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoad3.33795
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_UPATRE.SM37
Trapminesuspicious.low.ml.score
EmsisoftTrojan.Ppatre.Gen.1 (B)
IkarusTrojan-Downloader.Win32.Tiny
JiangminTrojanDropper.Dapato.aduh
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Downloader]/Win32.AGeneric
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Upatre!pz
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dapato.vho
GDataTrojan.Ppatre.Gen.1
VaristW32/Tiny.L.gen!Eldorado
AhnLab-V3Trojan/Win.Gen
Acronissuspicious
VBA32BScope.TrojanDownloader.Upatre
ALYacTrojan.Ppatre.Gen.1
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentTrojan-Dropper.Win32.Dapato.ka
YandexTrojan.DL.Tiny!DICkt4H4LrU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.C!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment