Trojan

Trojan:Win32/Upatre removal tips

Malware Removal

The Trojan:Win32/Upatre is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Upatre?


File Info:

crc32: DBE405DA
md5: 3f11c8cf00b421db710bab643fc43025
name: 3F11C8CF00B421DB710BAB643FC43025.mlw
sha1: 7e9c638f35f49ee364b72c1471d7f2c8d39a0916
sha256: 62cc5e0d5abf64d07bdc142f7920c4a366a3054ad25529be4d9a798c7cd27658
sha512: c61e1463325fbd1deb45b325d5f82cf7ef30af711157acea7dda18041c478d545e1b267df6a9f6bff396c33a5409f936c115673c26a3939c6947e65914b82211
ssdeep: 6144:8Vlw9brLnSogvpC2PVGsFdW1BjaJ2DGAVWQUgbkMQgwFyM6dUmKNjm8bWfsHVJ:Zbfn3epC2PVFdW1BDpDagwFyMVEkj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2006 Microsoft Corporation. All rights reserved.
InternalName: WinWord
FileVersion: 12.0.4518.1014
CompanyName: Microsoft Corporation
LegalTrademarks1: Microsoftxae is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windowsxae is a registered trademark of Microsoft Corporation.
ProductName: 2007 Microsoft Office system
ProductVersion: 12.0.4518.1014
FileDescription: Microsoft Office Word
OriginalFilename: WinWord.exe
Translation: 0x0000 0x04e4

Trojan:Win32/Upatre also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Lethic.Gen.4
FireEyeGeneric.mg.3f11c8cf00b421db
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXLH-OM!3F11C8CF00B4
CylanceUnsafe
SangforMalware
BitDefenderTrojan.Lethic.Gen.4
Cybereasonmalicious.f00b42
TrendMicroTROJ_GEN.R06CC0DKI20
CyrenW32/Agent.AOF.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Bskd-9753126-0
KasperskyHEUR:Trojan.Win32.Generic
RisingTrojan.Salgorea!1.BAD6 (CLASSIC)
Ad-AwareTrojan.Lethic.Gen.4
EmsisoftTrojan.Lethic.Gen.4 (B)
ComodoTrojWare.Win32.TrojanDropper.Agent.QQR@5t8sw7
F-SecureHeuristic.HEUR/AGEN.1113061
DrWebTrojan.MulDrop15.59569
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosMal/Generic-S
IkarusTrojan.Win32.Salgorea
JiangminTrojan.Generic.dncbk
AviraHEUR/AGEN.1113061
MAXmalware (ai score=82)
Antiy-AVLTrojan[Dropper]/Win32.Agent.mosn
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Upatre
ArcabitTrojan.Lethic.Gen.4
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.Salgorea.B
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C645160
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34634.Eq0@aiqw0Dpi
ALYacTrojan.Lethic.Gen.4
VBA32BScope.Trojan.Salgorea
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDropper.Agent.QRV
TrendMicro-HouseCallTROJ_GEN.R06CC0DKI20
YandexTrojan.GenAsa!rBpY9YUDYCs
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Agent.RRQ!tr
AVGWin32:Agent-AYZG [Cryp]
AvastWin32:Agent-AYZG [Cryp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Upatre?

Trojan:Win32/Upatre removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment