Threat Database Trojans Trojan.Upatre.VKD

Trojan.Upatre.VKD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 474
Threat Level: 80 % (High)
Infected Computers: 42,424
First Seen: November 2, 2021
Last Seen: July 31, 2026
OS(es) Affected: Windows

The detection of Trojan.Upatre.VKD on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the integrity of your computer, putting your personal data and online security at risk. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Upatre.VKD?

Trojan.Upatre.VKD is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan" refers to the mythological Trojan Horse, where enemies were hidden inside a gift. Similarly, Trojan malware hides within seemingly harmless software or files, waiting for the perfect moment to strike. The ".Upatre.VKD" part of the name may indicate specific characteristics or variants of the malware, but without more information, it's challenging to determine its exact nature or behavior.

How Trojan.Upatre.VKD Operates

Generally, Trojan horses like Trojan.Upatre.VKD operate by exploiting vulnerabilities in software or tricking users into installing them. Once installed, they can perform a wide range of malicious activities, including but not limited to, stealing personal data, installing additional malware, providing unauthorized access to the attacker, or disrupting system operation. The specific actions of Trojan.Upatre.VKD would depend on its design and the intentions of its creators, but the overarching goal is typically to compromise the security and privacy of the infected system.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely, depending on the malware's purpose. Common indicators include unusual system behavior, such as unexpected crashes, slow performance, or unfamiliar programs and icons. You might also notice increased network activity, even when you're not using the internet, or find that your antivirus software is disabled. Sometimes, the infection might not display obvious symptoms, making it harder to detect without proper scanning tools.

How to Remove Trojan.Upatre.VKD

  1. Boot your computer in Safe Mode with Networking. This will limit the malware's ability to interfere with the removal process while still allowing you to download necessary tools.
  2. Download and run a full scan with a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated to the latest version to increase its chances of detecting and removing the malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are sure are not necessary for your system's operation.
  4. Reset your web browsers (Google Chrome, Mozilla Firefox, Microsoft Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed. Repeat the scanning process until no threats are detected.

Conclusion

Removing Trojan.Upatre.VKD requires careful and systematic steps to ensure that all components of the malware are eliminated. It's also crucial to adopt preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus software, being cautious with email attachments and downloads, and avoiding suspicious websites. By taking these steps, you can protect your computer and personal data from the threats posed by Trojan horses and other types of malware.

Analysis Report

General information

Family Name: Trojan.Upatre.VKD
Signature status: No Signature

Known Samples

MD5: 3b143965e3e4a6c8684bdc597a92bbea
SHA1: 2804b565b7dc72ae5ff92ce6bc7b47b3eee18485
SHA256: 888DF097488303E3BB74E8F88622966BB82D9DF28A9BBE3DF462BDFF929B7F4B
File Size: 36.65 KB, 36652 bytes
MD5: e626ccbe5db5327b8bfd7b4da973b67d
SHA1: 055cff549997ac52dd8bd527665021ce10944e1d
SHA256: B63437D21BE5DB5EF83DC5A8C32B4CE47F7B3F2C5A7F00849412720033AE61A6
File Size: 47.13 KB, 47132 bytes
MD5: 0e0d816962c382d8348bd81fa7039619
SHA1: 2b4b6f5ef653ac1b69b3969469d0f8b2b24eba35
SHA256: 22D2834E066C25C058E4B69B23D3E10DBC298610E08FF770713EE892995B6DDD
File Size: 37.17 KB, 37172 bytes
MD5: ce333abd840d58c032382703f0fdab5b
SHA1: 3cbc9aafecdea9f62a9ef8161aaf8c53f0cb7606
SHA256: 181D77544E2E3ADCE004475B31A80DDD3C4F2C6A114FFE6208222DC2C144CD1C
File Size: 36.39 KB, 36392 bytes
MD5: 7b2fe495ea65c12ebbf48649e13b0a17
SHA1: 8c3a90cde3ccd621de02030312dcff55e9463246
SHA256: 1A7D9F44586613DA2DE6AF9AA2DADC62D634D39083D2454710F298F4C5E41B61
File Size: 37.97 KB, 37972 bytes
Show More
MD5: 74c52e4f705480fc69e6b9eb3c87ebc5
SHA1: 60009efb2e97f1e781032e28ff82a0106bea15a2
SHA256: 501DC4DA91856A40FDBB83189B5E1408B6439D1EBC67444184F013B9CD3078C6
File Size: 36.85 KB, 36852 bytes
MD5: b186eb06ef2f97351e230e9dfc15c8bc
SHA1: 55fb71e1a6a0ccab9de292bee98b030d2abf5315
SHA256: 28C5D45A501088C7FBE889F0CACD4FDD9A0E26091D5F9A040347E7453657F4A1
File Size: 36.37 KB, 36372 bytes
MD5: cce74f04e21f9463046fd816a5fad1e9
SHA1: a828785f162f788cfc7d870e610aa9749766504e
SHA256: B583F90531CDF6F09A356EC6D05016478F80F284FB70898A2DD067994E1DE83F
File Size: 40.89 KB, 40892 bytes
MD5: 64d735d22a16c7b9b01c1e786739982b
SHA1: 80b595544778867c9670df1cfbe35985ede73ef5
SHA256: 8AB84FEF52A2A2162A0EF1565639A7D4581323AFF9A51D5B1798DE75EE4BD246
File Size: 51.53 KB, 51532 bytes
MD5: 04d67bc5626c70a53ba8c492ed52608b
SHA1: 4eb6840f0c5eb1e9b9da24a8f138b154a6f67abe
SHA256: 99A85E6D87E193AC6119388715538572655892FC5AE82D10C0DF2BE6E56AF0CA
File Size: 49.45 KB, 49452 bytes
MD5: ad31bb360b00bbfa560ca72c5d502add
SHA1: c32e2c4540a4819b99f78dc17f41177a38f2ba05
SHA256: 41031A76511B02AC5488EDF98F2B0EC1D804AE431AB2BDEF19F995819C917318
File Size: 55.89 KB, 55892 bytes
MD5: bc0fc257d700d804071ab0ed6b8d917f
SHA1: 9ce6472b78b183ca6c96f86fc03a14dd08bd9e58
SHA256: 646D2272B03E5F4800402268CB392F81B01763D4B5CD7C492B56D0ABDD08B3A8
File Size: 38.23 KB, 38232 bytes
MD5: 051d7ff12cca69a355f2829b1940b65d
SHA1: f0700c937e64da5d098b7086d1229611bb8c80b6
SHA256: 9C27BFCEB838ECFAD849E96967849C8E446063177491A510B7D1255A5124853A
File Size: 36.97 KB, 36972 bytes
MD5: f981845fd343fefa1601b4e1ac21f5ff
SHA1: aee5031afe1546a015880870d2f30db23d18b3b0
SHA256: 891E87C4A2AE0A2D27CA9393A3D3A6F70682E5C8150991697F2460DF75F96823
File Size: 39.57 KB, 39572 bytes
MD5: 7afb472a1c7ae7fced516ae9f5bb0903
SHA1: d18b449cac9a854f59c95083a8a5056890797fbb
SHA256: 2D62F275DEB5C9E28AD6CF478C9489432F207E365A0813CF6D212D5CA26840B5
File Size: 38.57 KB, 38572 bytes
MD5: 45125581e78e515a6faf45b9b8236cde
SHA1: bedb9382ef17ab13116bed7eca59abd47a84ff43
SHA256: CE8A6834132938D1DA1861390FFE56AB17AB256E00D48045BAFE3A7E046D17C5
File Size: 42.41 KB, 42412 bytes
MD5: b1c79531ac787d710c5e9ad132e4904c
SHA1: 6948970bd1cd56fcc13dc2139fc784f30fadb89a
SHA256: FCA053F6A9892B83479BC3294E789B9AAE2817B6D47F48AB8C437E788B8099D0
File Size: 36.97 KB, 36972 bytes
MD5: 33f4c2f76706900fea880117b3d6fd05
SHA1: d79a79197bed0710c9c3c76e183f87f4f6ac545c
SHA256: 4C5E0C78860A6182EFFD973C11C4AEC4E723571426AC536F8D587FA0C3E497A8
File Size: 47.19 KB, 47192 bytes
MD5: 6e367beec2c69513923a736da5ecc28f
SHA1: 3192a01632cdbbeb0f4a6e70c2e0686ca96fddbf
SHA256: 91A1D332ED527D76A88342067030BE01A16864FB8A036C7ED92DA3CB849A9DCC
File Size: 43.85 KB, 43852 bytes
MD5: 2e81be7f5a24742b48bbde830e96d21f
SHA1: bfa3090b6a10a17701cfcdebf5a1ee8bd8421b2b
SHA256: 9A873556742BC04FE3A0E3CF2A81D964EB8591F1D351B08559FE257E3C295276
File Size: 39.15 KB, 39152 bytes
MD5: 8224130bbdddf6a7012fd92ae7d841a0
SHA1: 8f8669988442e94b7d8feb2596f6202db3b6cf9c
SHA256: EB9FF7D44939F6AB47920ECD969DE6502407C18C666CD64E51B5BC4EE63C62D5
File Size: 49.45 KB, 49452 bytes
MD5: 74b4be63d8a0414ed37628322bc0cb08
SHA1: a0c78a86c0be082ffc2721d70bf6952a0558be3e
SHA256: 43047123D980DAD450755764E075AEEC9DC28157BBD9F6C764B9BE9C11B42DDD
File Size: 36.95 KB, 36952 bytes
MD5: 889ae03c9c95b5cbfcaeb40642bf1179
SHA1: ec6e96df8afd8b39afc41df93769cdd4debdd269
SHA256: 38C705201911F25F8643DD11D31A31AFF5C19B60936BCE79F26BA59855F07C16
File Size: 38.55 KB, 38552 bytes
MD5: 1ebb801602fdf5deef3860134715db68
SHA1: dd72a35addef9a1dc1de7ee4545863fb30db83dd
SHA256: 727FC005D303BA6A66CC4B193CCE6404E15F8C9AA2EE038E8C6D9DBC5A605C70
File Size: 36.65 KB, 36652 bytes
MD5: 3857b0433c0594ae8342af7b9df0ad79
SHA1: 193c3ea6fbc8d1599e20e7aa0c76778c9a14ab9e
SHA256: E56DCFBD6C0BBAD71637FEB2DF8F95EF07714F495760C2AA653302E95402A322
File Size: 41.11 KB, 41112 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments www.tinytask.net
File Description www.tinytask.net
File Version 1, 77, 0, 0
Legal Copyright Copyright (c) 2019. All Rights Reserved.
Original Filename TinyTask.exe
Product Name TinyTask
Product Version 1, 77, 0, 0

File Traits

  • x86

Block Information

Total Blocks: 40
Potentially Malicious Blocks: 30
Whitelisted Blocks: 10
Unknown Blocks: 0

Visual Map

x x x 0 x x x x x x x x x x x x x x 0 0 0 0 x x x x x x x x x x 0 x 1 x 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Spy.KeyLogger.U
  • Upatre.VKD

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m!tX �� �v����(�*J*�"1�1HO@V�G�IH[u_�zb"hc�wk�ql(�q�X{b��P������������m��V����$�8წ���&M�=�S)�B1_T�Vw��`���%�������AE��"��D��&��$���LA*�" RegNtPreCreateKey

Windows API Usage

Category API
Keyboard Access
  • GetAsyncKeyState
  • GetKeyState
  • SetKeyboardState