Trojan

Trojan:Win32/Upatre!pz malicious file

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: 22E878BFBE11DB46715B.mlw
path: /opt/CAPEv2/storage/binaries/5b784b0a272955c88b042884c88a58034fd1981e1a566b4494ce349000bff0b3
crc32: F275547D
md5: 22e878bfbe11db46715b17605ea8bfc5
sha1: d964143e62526f3850f90714e85b4c928a6acf61
sha256: 5b784b0a272955c88b042884c88a58034fd1981e1a566b4494ce349000bff0b3
sha512: 17794a8b524dd3de41847298bad5d48a9215014ce2b58b7c619c192f0e837847f55126a61a9942524ce4865c461a3a9433af7661d3ae30a97568b68bf6ab4277
ssdeep: 192:rmQMKsn7vnKfzzRwXsA/ZpWL0sA+5GKsHskIAibBC/:mKA7fKfztU/Z0L0sAgsHAw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BD12963D6ED616B7D3B7DAB6C6F219C7F922B5223902880E409607440C23F56FDA574E
sha3_384: bf451ada3d2a2472b51f6f410a0b52f24c04e2afc685d2b41f48e6170b981c4cc50a9fce52614bd2096e75b9dc9152a1
ep_bytes: 8bec81c4f4feffffe8000000005b6681
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Upatre.1j!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Downloader.JQWQ
FireEyeGeneric.mg.22e878bfbe11db46
CAT-QuickHealTrojan.Verpackert.S12580624
SkyhighBehavesLike.Win32.Downloader.zt
ALYacTrojan.Downloader.JQWQ
Cylanceunsafe
ZillyaTrojan.Generic.Win32.831683
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 004b8d561 )
AlibabaTrojan:Win32/Upatre.341
K7GWTrojan-Downloader ( 004b8d561 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Downloader.JQWQ
SymantecDownloader.Upatre
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.F
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Dropper.Upatre-7194409-0
KasperskyHEUR:Trojan-Dropper.Win32.Dapato.vho
BitDefenderTrojan.Downloader.JQWQ
NANO-AntivirusTrojan.Win32.DownLoad3.dcdzpy
AvastWin32:Downloader-WFS [Trj]
TencentTrojan-DL.Win32.Waski.zc
EmsisoftTrojan.Downloader.JQWQ (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoad3.33795
VIPRETrojan.Downloader.JQWQ
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
SophosMal/Upatre-AS
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojan.Generic.aucae
VaristW32/A-7e979cf2!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Downloader]/Win32.AGeneric
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.BC@5qv3w8
MicrosoftTrojan:Win32/Upatre!pz
ViRobotTrojan.Win.Z.Upatre.9258
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan.PSE.17P1L14
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R120254
Acronissuspicious
McAfeeGenericATG-FABE!22E878BFBE11
MAXmalware (ai score=82)
VBA32BScope.TrojanDownloader.Upatre
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.B69C (CLASSIC)
YandexTrojan.GenAsa!BcZoWQSCCN0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.C!tr
BitDefenderThetaAI:Packer.3D76C6811E
AVGWin32:Downloader-WFS [Trj]
Cybereasonmalicious.e62526
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment