Trojan

What is “Trojan.Upatre.VT”?

Malware Removal

The Trojan.Upatre.VT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Upatre.VT virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Urdu (Pakistan)
  • Looks up the external IP address
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

icanhazip.com

How to determine Trojan.Upatre.VT?


File Info:

crc32: 77AA76D3
md5: 1ae30d836387e9b8a657b2bcba5dd7ce
name: 1AE30D836387E9B8A657B2BCBA5DD7CE.mlw
sha1: c597ddb23e61ac7f502da88d9cdab7392b0b50a3
sha256: 7fead94cd9a346cfb9866a67828dc55c5c7805f44684bab18fa6f8718b493ac0
sha512: 158bcbf97aae2224af42809490ff8918c66b131c0b508674b003cbb2044b2091405e0082dd3c92171dfef7f2f6df4df07388922627ee6f647204269adfc6b4d5
ssdeep: 768:1iXntYQpomI2vRJDQflsMhDtQYHWMfUchPvose:0XtNpDvRJDQGMhDtTHWMfDhYse
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Upatre.VT also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Upatre.Gen.3
FireEyeGeneric.mg.1ae30d836387e9b8
CAT-QuickHealTrojan.Kadena.B4
ALYacTrojan.Upatre.Gen.3
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.Upatre.Gen.3
K7GWTrojan-Downloader ( 0055c6c71 )
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
BitDefenderThetaGen:NN.ZexaF.34804.cqX@aOEQKkoG
CyrenW32/Upatre.AR.gen!Eldorado
SymantecDownloader.Upatre!gen5
BaiduWin32.Trojan.Kryptik.jw
APEXMalicious
ClamAVWin.Downloader.Upatre-5744092-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Upatre.epgxvo
ViRobotTrojan.Win32.Upatre.Gen.C
TencentMalware.Win32.Gencirc.10b55266
Ad-AwareTrojan.Upatre.Gen.3
SophosML/PE-A + Troj/Upatre-NU
ComodoTrojWare.Win32.TrojanDownloader.Upatre.BCF@5s4kib
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebTrojan.Upatre.3434
VIPRETrojan.Win32.Upatre.bv (v)
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Generic.ph
EmsisoftTrojan.Upatre.Gen.3 (B)
SentinelOneStatic AI – Malicious PE – Downloader
JiangminTrojan.Generic.azxgx
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=87)
Antiy-AVLTrojan[Downloader]/Win32.Upatre
ArcabitTrojan.Upatre.Gen.3
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Upatre.AE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R153955
Acronissuspicious
VBA32BScope.Trojan.Upatre
MalwarebytesTrojan.Upatre.VT
PandaTrj/Upatre.B
ESET-NOD32a variant of Win32/Kryptik.DLZD
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingTrojan.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!6Or+b80F0do
IkarusTrojan.Zmutzy
eGambitUnsafe.AI_Score_76%
FortinetW32/Daserf.B!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360HEUR/QVM02.0.0745.Malware.Gen

How to remove Trojan.Upatre.VT?

Trojan.Upatre.VT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment