Trojan

How to remove “Trojan:Win32/Upatre!pz”?

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: A0BCADB0BA3058B1AF7D.mlw
path: /opt/CAPEv2/storage/binaries/198ed3c0d7c08ea0ab5ee192543b41c0d36dba7dfb5cfeb8fa6a24b3f8c04644
crc32: D76F3459
md5: a0bcadb0ba3058b1af7d2a0534572ea7
sha1: babbe910a70c2a96d5d8b8cffa84d5eb35350d8a
sha256: 198ed3c0d7c08ea0ab5ee192543b41c0d36dba7dfb5cfeb8fa6a24b3f8c04644
sha512: fcbfe221ea5a27e05bd703ad2184a39eca9f8d3bb1f20e58bbcaf2762c263f02ee9b3bb88f466934b1423b04c3d1a0354e8ca5a19fecce5c759cd12d2aa41389
ssdeep: 768:dhwRJrgIUiPsED3VK2+ZtyOjgO4r9vFAg2rqzjtyEW2unNs0UGT:dCGiYTjipvF24tA2uNWGT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D7730E387ED659B2E377C6B281F682D2A931BC22BC52851F74CA374D0833E559C60E1E
sha3_384: 79285aad171bfac3c662df639b5df5cc3d1e5271ffe85ff0cde63545ae890aa31f43d32e72d62780cf4fc368f16bac92
ep_bytes: 558bec81ec3808000053565733f656ff
timestamp: 2013-10-30 10:58:20

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lY5V
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Downloader.JQDW
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.lz
McAfeeDownloader-FBVZ!A0BCADB0BA30
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Downloader.JQDW
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
AlibabaTrojan:Win32/Upatre.b686
K7GWTrojan-Downloader ( 0055f33b1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan-Downloader.Small.ck
VirITTrojan.Win32.DownLoad3.BPRD
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Small.AAB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.Upatre-10009077-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.JQDW
NANO-AntivirusTrojan.Win32.DownLoad3.dgmrrz
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Waski-A [Trj]
TencentTrojan-Downloader.Win32.Small.haa
EmsisoftTrojan.Downloader.JQDW (B)
F-SecureHeuristic.HEUR/AGEN.1317172
DrWebTrojan.DownLoad3.28161
ZillyaDownloader.SmallGen.Win32.3
TrendMicroTROJ_UPATRE.SMAZ
SophosTroj/Upatre-YW
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan/Generic.azrvz
WebrootW32.Trojan.Gen
VaristW32/S-b8568f35!Eldorado
AviraHEUR/AGEN.1317172
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.979
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.A@52i1eo
ArcabitTrojan.Downloader.JQDW
ViRobotTrojan.Win.Z.Upatre.75814
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Upatre!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
BitDefenderThetaGen:NN.ZexaE.36680.euZ@amDnDEni
MAXmalware (ai score=87)
VBA32Trojan.Download
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
RisingDownloader.Agent!1.C06E (CLASSIC)
YandexTrojan.GenAsa!xjw/xZS1BKE
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Waski-A [Trj]
Cybereasonmalicious.0a70c2
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment