Trojan

Trojan:Win32/Upatre!pz removal instruction

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: 57F8DAD5390FBA08D247.mlw
path: /opt/CAPEv2/storage/binaries/6faddde496026eabf95e330f8cd7af64bf08f1a5c594f2201fb84b86c604c836
crc32: C932E127
md5: 57f8dad5390fba08d247c3ae6ac2e49c
sha1: e5d12d1e40855c2dd197d3296906202ffdcee291
sha256: 6faddde496026eabf95e330f8cd7af64bf08f1a5c594f2201fb84b86c604c836
sha512: d1f0d7cfd9719e56dea27d724dc3902807bf2d03c449aae4ea4084e942274348b2ad8484c38166fd7c152b66afa29b67e9b81ee90133df987c659ee3470d8ae4
ssdeep: 192:Ptd+yUnwR2rhiJq6OJGn0kZn/+EYocLEbP/tr+HtJjLq:PeznwR2Q5me0w2EYduB+NJjLq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1315237796ED91677E3B7CAB6C5F252C7BA74B0233912DC4D50DB03840813F96ACA1A1E
sha3_384: 3e8e64f58651852a249f21bd4dceb9b945b5aeb1006b4662c22022409120739631cd365725b73852f33739343fca7fa7
ep_bytes: 558bec81ec3c08000053565733f656ff
timestamp: 2013-09-30 12:45:24

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lY5V
tehtrisGeneric.Malware
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanGen:Variant.Ser.Razy.12160
ClamAVWin.Downloader.Upatre-7598844-0
FireEyeGeneric.mg.57f8dad5390fba08
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.lz
ALYacGen:Variant.Ser.Razy.12160
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.WaskiGen.Win32.3
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Upatre.b686
K7GWTrojan-Downloader ( 004b972f1 )
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
BitDefenderThetaGen:NN.ZexaF.36744.auY@ayY5q3bi
SymantecDownloader.Upatre!gm
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Razy.12160
NANO-AntivirusTrojan.Win32.DownLoad3.dpbiod
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Downloader-WID [Trj]
TencentTrojan.Win32.Downloader.wb
EmsisoftGen:Variant.Ser.Razy.12160 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
BaiduWin32.Trojan-Downloader.Waski.k
VIPREGen:Variant.Ser.Razy.12160
TrendMicroTROJ_UPATRE.SMAS
Trapminesuspicious.low.ml.score
SophosTroj/Upatre-YW
IkarusTrojan-Downloader.Win32.Upatre
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan/Generic.azrzv
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.Waski.a
XcitiumTrojWare.Win32.TrojanDownloader.Small.CDC@8mzsfr
ArcabitTrojan.Ser.Razy.D2F80
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Upatre!pz
VaristW32/S-dd480c14!Eldorado
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
McAfeeGenericRXUB-BS!57F8DAD5390F
MAXmalware (ai score=83)
VBA32Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAS
RisingDownloader.Agent!1.C06E (CLASSIC)
YandexTrojan.GenAsa!xjw/xZS1BKE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Waski.A!tr
AVGWin32:Downloader-WID [Trj]
Cybereasonmalicious.e40855
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment