Trojan

About “Trojan:Win32/Upatre!pz” infection

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: 3B84187034C46C4A542D.mlw
path: /opt/CAPEv2/storage/binaries/39929879f282456c19d11f9918f999cb9bfe6dcb1627a8950cfd8de53d719d7c
crc32: 2E91D29E
md5: 3b84187034c46c4a542dd03b6f75977b
sha1: e2a161b9b525277f450f079bc5c9893381d3550b
sha256: 39929879f282456c19d11f9918f999cb9bfe6dcb1627a8950cfd8de53d719d7c
sha512: b1e048adc3ca24dc539f7c1bcd3f8152c17d2be71df31f25397d828e00493d05f49044ada42d6ce1d956bad6851b8eb522c037796332272fbdd9f3b26f795796
ssdeep: 192:rmQMKsnAwnKfzzRwEw1tMVz7Dn5UE0WJc+qo537:mKAFKfztzoKVXdB5r
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171F1CC3E6EC515B7D377DAB686F218CBFA62B1233902494E408307440C23F97EEA564E
sha3_384: 87bc96f30029cbdb2c6c93afe33fd03f167fe8538ada5a682d4e52871c488c125c576f31eb16e21108b7ea8c12f51bfa
ep_bytes: 8bec81c4f4feffffe8000000005b6681
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Upatre.1j!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Downloader.JQWQ
CAT-QuickHealTrojan.Verpackert.S12580624
SkyhighBehavesLike.Win32.Downloader.zt
McAfeeGenericATG-FABE!3B84187034C4
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Downloader.JQWQ
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 004b8d561 )
BitDefenderTrojan.Downloader.JQWQ
K7GWTrojan-Downloader ( 004b8d561 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.3D76C6811E
SymantecDownloader.Upatre
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.F
APEXMalicious
ClamAVWin.Dropper.Upatre-7194409-0
KasperskyHEUR:Trojan-Dropper.Win32.Dapato.vho
AlibabaTrojan:Win32/Upatre.341
NANO-AntivirusTrojan.Win32.DownLoad3.dcdzpy
ViRobotTrojan.Win.Z.Waski.7932.AQ
RisingDownloader.Waski!1.B69C (CLASSIC)
SophosMal/Upatre-AS
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoad3.33795
ZillyaDownloader.Waski.Win32.80727
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3b84187034c46c4a
EmsisoftTrojan.Downloader.JQWQ (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=83)
JiangminTrojan.Generic.aucae
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/A-7e979cf2!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.AGeneric
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Upatre!pz
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.BC@5qv3w8
ArcabitTrojan.Downloader.JQWQ
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dapato.vho
GDataWin32.Trojan.PSE.17P1L14
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R120254
Acronissuspicious
VBA32BScope.TrojanDownloader.Upatre
ALYacTrojan.Downloader.JQWQ
TACHYONTrojan-Downloader/W32.Upatre.7932.F
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentTrojan-DL.Win32.Waski.zc
YandexTrojan.GenAsa!BcZoWQSCCN0
IkarusTrojan-Downloader.Win32.Waski
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.C!tr
AVGWin32:Downloader-WFS [Trj]
Cybereasonmalicious.9b5252
AvastWin32:Downloader-WFS [Trj]

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment