Trojan

Trojan:Win32/Upatre!pz removal instruction

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: A1EB74CF55905C13E546.mlw
path: /opt/CAPEv2/storage/binaries/9e552e5f356e4f35d682714b74487613d11511374cc8aa356a00ee27bdf139ce
crc32: 42B405ED
md5: a1eb74cf55905c13e5467775e504f7ef
sha1: b561a2cf7cd62764fe2c0d5f24f6e1e76473ad9b
sha256: 9e552e5f356e4f35d682714b74487613d11511374cc8aa356a00ee27bdf139ce
sha512: f18337d8b10a403faac29e5e4b597d7e6bbc13255ceea3fdad539fcb05ce2d0f12e4f3bbe435d67818f286480598c18b5369f418cb55fbd448a0098dd33cdfdf
ssdeep: 384:KK+fKfzsqud1lubAK0s2y5V9yGQRSVnWLglNqghzmw:f+fAQqud1lKAKmy5ne+9l8gVmw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16F03F13D6ED52672E3BBDAB6CAF655C7B975B0233D02680D409743440823F57AEE1A0E
sha3_384: 170e81f910808d482f80296fe8c038f712b71c61d7921dce00c3abfad5cae63ebca0732f22bccaca0892f0b137c795f5
ep_bytes: 8bec81c4f4feffffe8000000005b6681
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.100204
ClamAVWin.Dropper.Upatre-9917176-0
CAT-QuickHealTrojan.Verpackert.S12580624
SkyhighBehavesLike.Win32.Downloader.pz
McAfeeGenericATG-FABE!A1EB74CF5590
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Waski.Win32.50102
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
K7GWTrojan-Downloader ( 0049d22b1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D1876C
VirITTrojan.Win32.Upatre.CN
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.F
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Dropper.Win32.Dapato.gen
BitDefenderTrojan.GenericKDZ.100204
NANO-AntivirusTrojan.Win32.DownLoad3.deckqy
AvastWin32:TrojanX-gen [Trj]
RisingDownloader.Waski!1.B69C (CLASSIC)
EmsisoftTrojan.GenericKDZ.100204 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoad3.33795
VIPRETrojan.GenericKDZ.100204
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a1eb74cf55905c13
SophosMal/Upatre-AS
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.aucae
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan[Downloader]/Win32.Waski
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.BC@5qv3w8
MicrosoftTrojan:Win32/Upatre!pz
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dapato.gen
GDataWin32.Trojan.PSE1.1ND8CBC
VaristW32/S-f170c96e!Eldorado
AhnLab-V3Trojan/Win32.Agent.R120254
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.ciY@aC3byNg
VBA32Trojan.Download
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan-DL.Win32.Waski.zc
YandexTrojan.Agent!c6HVycSAdIo
IkarusTrojan-Downloader.Win32.Waski
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.C!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.f7cd62
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment