Trojan

Trojan:Win32/Upatre!pz (file analysis)

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: EC1FB045E47A60C103F4.mlw
path: /opt/CAPEv2/storage/binaries/efc81e7b922bfc658cec540a10e0e990c925cb5a4aa332ba7b7e87954ad67a3b
crc32: 3528CA30
md5: ec1fb045e47a60c103f44622fd2c1ec5
sha1: 0ad235e68d4a53b27b97b6f0093e4beb8f1444ad
sha256: efc81e7b922bfc658cec540a10e0e990c925cb5a4aa332ba7b7e87954ad67a3b
sha512: 69aa6425659c8ac4151744612a110a3b8ade9dc1c043c69bacf04c0bc7eb565ad6b1724fe5fd4f74f572a92dd5faad6d3e1de16d8b26e6afe2f370c0760cb64d
ssdeep: 768:dwowRmYl50PsED3VK2+ZtyOjgO4r9vFAg2rqfe4mvH8A3kSnjbZ6/cBtGi2Xf:dwl36YTjipvF234wRkSnj0/cqtf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19283CB387AD955B2E37BC67685F681D6A935BC237C51881F248B334D0C33F56ACA0A1E
sha3_384: 72d430ad0b1512791d9c2379a9c1cd81617d56cfa440d013e3aeb03243c26e1361cfad3dac861fb1761fb59c297c6eca
ep_bytes: 558bec81ec3808000053565733f656ff
timestamp: 2013-10-30 10:58:20

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanTrojan.Downloader.JQDW
ClamAVWin.Downloader.Upatre-9903172-0
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.mz
McAfeeDownloader-FBVZ!EC1FB045E47A
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.SmallGen.Win32.3
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 0055f33b1 )
Cybereasonmalicious.68d4a5
ArcabitTrojan.Downloader.JQDW
BitDefenderThetaGen:NN.ZexaE.36680.fuZ@amDnDEni
VirITTrojan.Win32.DownLoad3.BPRD
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.JQDW
NANO-AntivirusTrojan.Win32.DownLoad3.dgmrrz
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Waski-A [Trj]
TencentTrojan-Downloader.Win32.Small.haa
EmsisoftTrojan.Downloader.JQDW (B)
F-SecureHeuristic.HEUR/AGEN.1317172
BaiduWin32.Trojan-Downloader.Small.ck
VIPRETrojan.Downloader.JQDW
TrendMicroTROJ_UPATRE.SMAZ
SophosTroj/Upatre-YW
IkarusTrojan-Downloader.Win32.Upatre
JiangminTrojan/Generic.azrvz
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1317172
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.998
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.A@52i1eo
MicrosoftTrojan:Win32/Upatre!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Upatre.BJ
VaristW32/S-b8568f35!Eldorado
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
VBA32Trojan.Download
ALYacTrojan.Downloader.JQDW
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
RisingDownloader.Agent!1.C06E (CLASSIC)
YandexTrojan.GenAsa!xjw/xZS1BKE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Waski-A [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment