Trojan

Trojan:Win32/Upatre!pz malicious file

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: 72590266AF4DCA7379B1.mlw
path: /opt/CAPEv2/storage/binaries/f590be1aaf8dc7c42a5a854222ed50a077c464bec89312b2d2ada39b363b73bb
crc32: 8DF1F205
md5: 72590266af4dca7379b132b7ab54d235
sha1: 07751843dcadd773aadd0b72766bb23f0d02ba4a
sha256: f590be1aaf8dc7c42a5a854222ed50a077c464bec89312b2d2ada39b363b73bb
sha512: d5b61abe781f6d9a51eaa1c4b4619aaf8bf67b2b20987dcf75d3d5073da6721cf8f3bbbb342db936273e1b3189c8700b2ae673aa438e436752c9aca735cefa5b
ssdeep: 192:fttu9J8nwR27ITZO+mGlOPGr9MyR4eL1eEJuBjLF8Zaq5UnQ:fnnwR28gGlOPGt4ox0KgqWnQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12D52003C6ED55572E37BCAB6C9F255C6FA61B46339029C0E80DB03810813F97ADE1A1E
sha3_384: 532d0ab9a874762805f8512562c51a4e15dca7d421f37963182342c87de6680b37360f6845230667ac49afc6261a8575
ep_bytes: 558bec81ec3c04000053565733f656ff
timestamp: 2013-09-03 19:13:33

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.71194909
CAT-QuickHealTrojanDownlder.Upatre.MUE.A5
SkyhighBehavesLike.Win32.Generic.lz
McAfeeGenericRXUB-BS!72590266AF4D
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKD.71194909
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 0048f6391 )
Cybereasonmalicious.6af4dc
BaiduWin32.Trojan-Downloader.Waski.k
VirITTrojan.Win32.Generic.BNHU
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Downloader.Upatre-10018147-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.71194909
NANO-AntivirusTrojan.Win32.DownLoad3.emvztu
AvastWin32:Downloader-WID [Trj]
TencentTrojan.Win32.Downloader.wb
SophosTroj/Upatre-YW
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoad3.28161
ZillyaDownloader.Waski.Win32.80002
TrendMicroTROJ_UPATRE.SMAS
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.72590266af4dca73
EmsisoftTrojan.GenericKD.71194909 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
JiangminTrojanDownloader.Generic.akum
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Upatre.MR.gen!Eldorado
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Upatre!pz
XcitiumTrojWare.Win32.TrojanDownloader.Small.CDC@8mzsfr
ArcabitTrojan.Generic.D43E591D
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.10H4FHC
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36802.auY@aq7Avgpi
ALYacTrojan.GenericKD.71194909
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAS
RisingDownloader.Agent!1.E264 (CLASSIC)
YandexTrojan.GenAsa!xjw/xZS1BKE
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Downloader-WID [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment