Trojan

What is “Trojan:Win32/Upatre!pz”?

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: 00155B33C999AE7669E8.mlw
path: /opt/CAPEv2/storage/binaries/3612a375192f411c28a4a892b0101a0f105f147d865f94a2e71181be6e00f93b
crc32: E20D3663
md5: 00155b33c999ae7669e81dea73d8ca1e
sha1: af0b9a14ee6faa62e9eafb444e35cf7bd10f4ba6
sha256: 3612a375192f411c28a4a892b0101a0f105f147d865f94a2e71181be6e00f93b
sha512: 0eec469a6d6f21656c21d9eafb846843871e4ac8981022328a575065edcaa67c26d089ed48522594ff88beede773eb38079c241f611780e76a76e75139d99006
ssdeep: 192:SIUjlLPnwR2bwJlNBi6t35nhPShp2a172lsZbmeSoe4lSRiq/lu/:SJ5PnwR2cJlNDpJShosZiP4YRf6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B682113C6ED51573E3BBCAB6C9F255CAF965B42339029C0E50DB03850C13F96ADA1A1E
sha3_384: 520a12ddd69ad9b7163fce51a01d53e61a89f8eff7233ad8c248e5988bddf59a6e8024de343d21f5d8d11cf293c67782
ep_bytes: 558bec81ec3c08000053565733f656ff
timestamp: 2013-09-27 06:50:01

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.70681758
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.lz
ALYacTrojan.GenericKD.70681758
Cylanceunsafe
ZillyaDownloader.Waski.Win32.13344
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 004b972f1 )
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
ArcabitTrojan.Generic.D436849E
BaiduWin32.Trojan-Downloader.Waski.k
SymantecDownloader.Upatre!gm
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.Upatre-7598843-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.GenericKD.70681758
NANO-AntivirusTrojan.Win32.DownLoad3.dpbiod
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Downloader-WID [Trj]
TencentTrojan.Win32.Downloader.wb
EmsisoftTrojan.GenericKD.70681758 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoad3.28161
VIPRETrojan.GenericKD.70681758
TrendMicroTROJ_UPATRE.SMAZ
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.00155b33c999ae76
SophosTroj/Upatre-YW
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.azrzv
WebrootW32.Trojan.Gen
VaristW32/Upatre.KG.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Small.CDC@8mzsfr
MicrosoftTrojan:Win32/Upatre!pz
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
GoogleDetected
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
McAfeeGenericRXUB-BS!00155B33C999
VBA32Trojan.Downloader
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
RisingDownloader.Agent!1.C06E (CLASSIC)
YandexTrojan.GenAsa!xjw/xZS1BKE
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.36608.buY@aS6jtqpi
AVGWin32:Downloader-WID [Trj]
Cybereasonmalicious.4ee6fa
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment