Trojan

Trojan:Win32/Upatre!pz removal instruction

Malware Removal

The Trojan:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre!pz?


File Info:

name: EE33A7848968510947A2.mlw
path: /opt/CAPEv2/storage/binaries/1173dfcebbdc3a67ee417224d82a673230c9d91a896aa444c7105cc2d3e58305
crc32: 2C1A88F0
md5: ee33a7848968510947a2b574b7f05cdf
sha1: de0da2c156295fd74e4833a9ea0cad19c7f7bb4d
sha256: 1173dfcebbdc3a67ee417224d82a673230c9d91a896aa444c7105cc2d3e58305
sha512: cc65b89b2834b36bda1d32a61d9dd4b76d74bf8c63375726e594116fdcacee30ed0bc88040b37e88660213055e930ae5ace780015c89f7ed197b3811a787655c
ssdeep: 768:dwowRmYl50PsED3VK2+ZtyOjgO4r9vFAg2rqfe4mvH8A3kSnjbZ6/cBtGi2Xn:dwl36YTjipvF234wRkSnj0/cqtn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F783CB387AD955B2E37BC67685F681D6A935BC227C51881F348B334D0C33F56ACA0A1E
sha3_384: 80a473daff704017be7a73c7a0077c18dd0e7d5368a6a525022c7cbe4a86e9181053f1f0a8eea5437f10431451999408
ep_bytes: 558bec81ec3808000053565733f656ff
timestamp: 2013-10-30 10:58:20

Version Info:

0: [No Data]

Trojan:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Downloader.JQDW
ClamAVWin.Downloader.Upatre-9903172-0
FireEyeGeneric.mg.ee33a78489685109
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.lz
McAfeeDownloader-FBVZ!EE33A7848968
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.SmallGen.Win32.3
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
BitDefenderTrojan.Downloader.JQDW
K7GWTrojan-Downloader ( 0055f33b1 )
Cybereasonmalicious.156295
BaiduWin32.Trojan-Downloader.Small.ck
VirITTrojan.Win32.DownLoad3.BPRD
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.DownLoad3.dgmrrz
RisingDownloader.Agent!1.C06E (CLASSIC)
EmsisoftTrojan.Downloader.JQDW (B)
F-SecureHeuristic.HEUR/AGEN.1317172
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Downloader.JQDW
TrendMicroTROJ_UPATRE.SMAZ
SophosTroj/Upatre-YW
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan/Generic.azrvz
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1317172
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.998
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.A@52i1eo
ArcabitTrojan.Downloader.JQDW
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Upatre!pz
VaristW32/S-b8568f35!Eldorado
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
VBA32Trojan.Download
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
TencentTrojan-Downloader.Win32.Small.haa
YandexTrojan.GenAsa!xjw/xZS1BKE
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaE.36680.euZ@amDnDEni
AVGWin32:Waski-A [Trj]
AvastWin32:Waski-A [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Upatre!pz?

Trojan:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment