Trojan

Trojan:Win32/Upatre!pz removal tips

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: EA850D84DFAED30BC087.mlw
path: /opt/CAPEv2/storage/binaries/9ef1a47d3faac776090e67d583119e3a86fd103c128c8e87ecce5e1fa55e418f
crc32: 56A03D3E
md5: ea850d84dfaed30bc087d291106194a5
sha1: 7e76cebff9299dfc5d79dcbcd6f2b19f877f6d09
sha256: 9ef1a47d3faac776090e67d583119e3a86fd103c128c8e87ecce5e1fa55e418f
sha512: 76173ed7328a565fc54a83cd572d15f2697111f142f7487389a72d7d60cffde397d6ac8092b934913d167f676e8a54b140be90eb5a887aaea9ee1f51754852e9
ssdeep: 192:NmUWKs/vnKfzsqN8dg4lDcoQNbAR700F644RmxHs2+1Hu+cMroaEXp4hc0BrNZxD:KK+fKfzsqud1lubAK0s2y5dro54fN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1960329397ED96572E7BFDAB6CAF255C7B975B0223D02680D408643440C23F56EEA1B0E
sha3_384: 14fb00ff97beef3fb7906519d5d1e4e70a9c089861b00a0308206cc98f3b044991b32d1c306c588db94f490dae4e429b
ep_bytes: 8bec81c4f4feffffe8000000005b6681
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Waski.b!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.33795
MicroWorld-eScanTrojan.GenericKDZ.100204
ClamAVWin.Dropper.Upatre-9917176-0
FireEyeGeneric.mg.ea850d84dfaed30b
CAT-QuickHealTrojan.Verpackert.S12580624
SkyhighBehavesLike.Win32.Downloader.nz
McAfeeGenericATG-FABE!EA850D84DFAE
Cylanceunsafe
ZillyaDownloader.Waski.Win32.50102
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
AlibabaTrojan:Win32/Upatre.341
K7GWTrojan-Downloader ( 0049d22b1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D1876C
BitDefenderThetaGen:NN.ZexaF.36608.ciY@aC3byNg
VirITTrojan.Win32.Upatre.CN
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.F
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Dropper.Win32.Dapato.gen
BitDefenderTrojan.GenericKDZ.100204
NANO-AntivirusTrojan.Win32.DownLoad3.deckqy
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-DL.Win32.Waski.zc
SophosMal/Upatre-AS
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.GenericKDZ.100204
TrendMicroTROJ_GEN.R002C0DLN23
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.100204 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.aucae
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Downloader]/Win32.Waski
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.BC@5qv3w8
MicrosoftTrojan:Win32/Upatre!pz
ViRobotTrojan.Win.Z.Waski.40052
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dapato.gen
GDataWin32.Trojan.PSE1.1ND8CBC
VaristW32/S-f170c96e!Eldorado
AhnLab-V3Trojan/Win32.Agent.R120254
Acronissuspicious
VBA32Trojan.Download
ALYacTrojan.GenericKDZ.100204
MAXmalware (ai score=88)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLN23
RisingDownloader.Waski!1.B69C (CLASSIC)
YandexTrojan.Agent!c6HVycSAdIo
IkarusTrojan-Downloader.Win32.Waski
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.C!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.ff9299
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment