Trojan

About “Trojan:Win32/Upatre!pz” infection

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: 0545823663F33599C6B3.mlw
path: /opt/CAPEv2/storage/binaries/a2f6ca24eba590dd7e9f5715425590758fd9335da9fb5fd02b1bd9e06170e09f
crc32: DFBE5DE0
md5: 0545823663f33599c6b31bfd5ff6be46
sha1: 90c7d987d5b640b5230fa96873d5cc7d49635945
sha256: a2f6ca24eba590dd7e9f5715425590758fd9335da9fb5fd02b1bd9e06170e09f
sha512: 36dbc081174403392f60a03aa25ffc28b5cba646ddff0c6290551e4f18db750a5acd5d6ad2bf1b4adea911f600a153a68c13476ae4f9e211d2c24bd6f2180082
ssdeep: 384:SJ5PnwR2cJlNDpJShosZiP4YRfM9C0yUWC:Y5fwR9ZCosZiwYC9C0y3C
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B92013C6ED51573E37BCAB6C9F255CBF965B42339029C0E50DB03850823F96ADA1A1E
sha3_384: c5a4853e96bdfab61b401a9f737c811fb699310e9e698d2b78fc2018561a001e7cc3047ae807f82b45e2c72f98339a3b
ep_bytes: 558bec81ec3c08000053565733f656ff
timestamp: 2013-09-27 06:50:01

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.70681758
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.mz
McAfeeGenericRXUB-BS!0545823663F3
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKD.70681758
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 004b972f1 )
Cybereasonmalicious.7d5b64
BaiduWin32.Trojan-Downloader.Waski.k
SymantecDownloader.Upatre!gm
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.Upatre-7598843-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.GenericKD.70681758
NANO-AntivirusTrojan.Win32.DownLoad3.dpbiod
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Downloader-WID [Trj]
TencentTrojan.Win32.Downloader.wb
EmsisoftTrojan.GenericKD.70681758 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoad3.28161
ZillyaDownloader.Waski.Win32.13344
TrendMicroTROJ_UPATRE.SMAZ
SophosTroj/Upatre-YW
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan/Generic.azrzv
WebrootW32.Trojan.Gen
VaristW32/Upatre.KG.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Small.CDC@8mzsfr
ArcabitTrojan.Generic.D436849E
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
MicrosoftTrojan:Win32/Upatre!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.buY@aS6jtqpi
ALYacTrojan.GenericKD.70681758
VBA32Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
RisingDownloader.Agent!1.C06E (CLASSIC)
YandexTrojan.GenAsa!xjw/xZS1BKE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Waski.A!tr
AVGWin32:Downloader-WID [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment