Trojan

Trojan:Win32/Upatre!pz removal instruction

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: 02187501639EE9E493AC.mlw
path: /opt/CAPEv2/storage/binaries/7de33ebc5728e82e2a6b1d356c48e5ebecf18384252c200cc4d5c05270df6222
crc32: 9FDE5132
md5: 02187501639ee9e493acb99d5a414029
sha1: ae4a90d80ca1d8809fb162c5f4ba74bdcd6f728d
sha256: 7de33ebc5728e82e2a6b1d356c48e5ebecf18384252c200cc4d5c05270df6222
sha512: ee3acd7c2f4af4200f454d26aa8efb2ed030730ff578df57efb981afe187cbb04439188ddd8461ee5cfb678b1833dad534a68426b29355600dc217965386f325
ssdeep: 192:dBR0donwR2FFFLBfoZvrzqfR572WhyBQFAd1e/il2:dNnwR2FvVot+X7BAmCd1P2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T103E224386ED916B2E3B7DAB6C6F645C6FE75B4233911980E40DB03450C13F57ADA1A0E
sha3_384: e53a661269ac1a91a74e25bf1b2bf6be7cf249b19917f49ce129b9dca822058e6dd9b04a8877ad484e6f2c9fdd73ab25
ep_bytes: 558bec81ec3808000053565733f656ff
timestamp: 2013-10-30 10:58:20

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.02187501639ee9e4
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Dropper.nz
McAfeeGenericRXUB-BS!02187501639E
MalwarebytesTrojan.Upatre.Generic
ZillyaDownloader.SmallGen.Win32.3
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 0055f33b1 )
Cybereasonmalicious.80ca1d
ArcabitTrojan.Downloader.JQDW
BaiduWin32.Trojan-Downloader.Small.ck
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
ClamAVWin.Downloader.Upatre-10009077-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Downloader.JQDW
NANO-AntivirusTrojan.Win32.DownLoad3.dgmrrz
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
MicroWorld-eScanTrojan.Downloader.JQDW
AvastWin32:Waski-A [Trj]
TencentTrojan-Downloader.Win32.Small.haa
SophosTroj/Upatre-YW
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Downloader.JQDW
TrendMicroTROJ_UPATRE.SMAZ
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Downloader.JQDW (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.azrvz
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.Waski.a
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.A@52i1eo
MicrosoftTrojan:Win32/Upatre!pz
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
VaristW32/S-654ac031!Eldorado
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
VBA32Trojan.Download
ALYacTrojan.Downloader.JQDW
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
RisingDownloader.Agent!1.C06E (CLASSIC)
YandexTrojan.DL.Small!yvz3qmW1VgI
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.36744.cuY@amDnDEni
AVGWin32:Waski-A [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment