Trojan

Trojan:Win32/Upatre!pz information

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: 525C1D459BB100166A97.mlw
path: /opt/CAPEv2/storage/binaries/a03cec5fdd782a443cebe1e0e25762229e95e3e8ae1a4604417ab14b95c0248a
crc32: 346B5781
md5: 525c1d459bb100166a979de16ce71923
sha1: db80fd5feca73cd7a28d4d3e5094b8b247ac9504
sha256: a03cec5fdd782a443cebe1e0e25762229e95e3e8ae1a4604417ab14b95c0248a
sha512: aea9b534c1047c73398df49e86e910ebaa3a24587eab5772df84082fc17cab8c6330d94174b7d18e5adddcf57bd69da498438ab40b63b3531208f6763fae9e1a
ssdeep: 384:kKAaKfzS9Hx1pJnJoxdSH9lXqEU7GcR6N5OmrJ:hAaAoHx1pJJoxdiXG9E5Oml
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11C821E3C6EE91673E3BBCABAC6F255C7F976B4223902580D509603440C23F57BDA1A5E
sha3_384: 0337a1bbbc09c0b3aa12fefe1c769770744af69e47509b972f1c86d2b487bbdddc55fe49df7e2f46d710d91cffdf3fc8
ep_bytes: 8bec81c4f4feffffe8000000005b6681
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
AVGWin32:Downloader-WFS [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Downloader.JQWQ
CAT-QuickHealTrojan.Verpackert.S12580624
SkyhighBehavesLike.Win32.Downloader.lt
McAfeeGenericATG-FABE!525C1D459BB1
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Generic.Win32.707251
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 004b8d561 )
K7GWTrojan-Downloader ( 004b8d561 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Downloader.JQWQ
SymantecDownloader.Upatre
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Waski.F
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.Upatre-7350939-0
KasperskyHEUR:Trojan-Dropper.Win32.Dapato.vho
BitDefenderTrojan.Downloader.JQWQ
NANO-AntivirusTrojan.Win32.DownLoad3.dcdzpy
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Downloader-WFS [Trj]
TencentTrojan-DL.Win32.Waski.zc
EmsisoftTrojan.Downloader.JQWQ (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoad3.33795
VIPRETrojan.Downloader.JQWQ
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.525c1d459bb10016
SophosMal/Upatre-AS
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojan.Generic.aucae
VaristW32/A-7e979cf2!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Downloader]/Win32.AGeneric
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.BC@5qv3w8
MicrosoftTrojan:Win32/Upatre!pz
ViRobotTrojan.Win32.Agent.15560
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dapato.vho
GDataWin32.Trojan.PSE.17P1L14
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R120254
Acronissuspicious
VBA32BScope.TrojanDownloader.Upatre
ALYacTrojan.Downloader.JQWQ
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingDownloader.Waski!1.B69C (CLASSIC)
YandexTrojan.GenAsa!BcZoWQSCCN0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.C!tr
BitDefenderThetaAI:Packer.222ACFA21E
Cybereasonmalicious.59bb10
DeepInstinctMALICIOUS
alibabacloudDownloader.Win32.Upatre.d01c5225

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment