Malware

Should I remove “Mal/Generic-S + Mal/Upatre-AS”?

Malware Removal

The Mal/Generic-S + Mal/Upatre-AS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Mal/Upatre-AS virus can do?

  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Mal/Generic-S + Mal/Upatre-AS?


File Info:

name: E1462DE44469287ECE34.mlw
path: /opt/CAPEv2/storage/binaries/3966017d8cc265ba64c2a9272c47aa7b65f589bcc3c926e58c8f608b31084b56
crc32: AFF791AD
md5: e1462de44469287ece34ff0316277803
sha1: 5bced3bfcaff91bc00c7394cfebb24331f551014
sha256: 3966017d8cc265ba64c2a9272c47aa7b65f589bcc3c926e58c8f608b31084b56
sha512: dff80ed18393f0b842d943eb63dab7781212d47603e6f34456d23a326d6a3b1a48f975365092a08f38dd689f211d73cbeb9d3644d74853f4e579507519e7ba1d
ssdeep: 192:jQ3FRWwnzigCaRO4W3OmWXVAAgjxNsUE4BOdYeM4A4KLQS7cwqRO2Vn+:/4ziTa84W3Onl/g1fOdYut0Y+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1296238785AF95672E37BCEBA9AF651C6FC70B4223E02580D808743450823F96DDA1B5F
sha3_384: eb1624d00c0a62aecaf1d2eb72545e2b48ebf6017cdf4699f5a387c09d9ba0ab70eae4b901d423b59c4124457369a8f3
ep_bytes: 8bec81c410ffffffe8000000005b6681
timestamp: 2014-07-07 08:12:37

Version Info:

0: [No Data]

Mal/Generic-S + Mal/Upatre-AS also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.33795
MicroWorld-eScanTrojan.Generic.30260827
FireEyeGeneric.mg.e1462de44469287e
CAT-QuickHealDownldr.Upatre.S12612429
ALYacTrojan.Generic.30260827
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_2ad4.None
K7GWTrojan-Downloader ( 0049d22b1 )
K7AntiVirusTrojan-Downloader ( 0049d22b1 )
BitDefenderThetaAI:Packer.34AAEF9E1E
CyrenW32/Trojan.EIBJ-5084
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.F
TrendMicro-HouseCallTROJ_GEN.R002C0DL921
Paloaltogeneric.ml
KasperskyUDS:Trojan-Downloader.Win32.Small.gen
BitDefenderTrojan.Generic.30260827
NANO-AntivirusTrojan.Win32.DownLoad3.dceouh
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
RisingTrojan.Generic@ML.100 (RDML:40M579liwtRMli83iBtQmw)
Ad-AwareTrojan.Generic.30260827
EmsisoftTrojan.Generic.30260827 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.VP@8ckbcs
VIPRETrojan.Win32.Upatre.zz (v)
TrendMicroTROJ_GEN.R002C0DL921
McAfee-GW-EditionBehavesLike.Win32.Generic.lt
SophosMal/Generic-S + Mal/Upatre-AS
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Generic.bcqm
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.TSGeneric
GridinsoftRansom.Win32.Zbot.sa
MicrosoftTrojan:Win32/Zbot.Dk!MTB
ViRobotTrojan.Win32.Z.Waski.14622.D
GDataTrojan.Generic.30260827
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R120254
Acronissuspicious
McAfeeGenericATG-FABE!E1462DE44469
MAXmalware (ai score=80)
VBA32TrojanSpy.Zbot
MalwarebytesTrojan.Upatre.Generic
PandaTrj/Genetic.gen
APEXMalicious
TencentMalware.Win32.Gencirc.10b0ce38
YandexTrojan.GenAsa!+b10tL5tlnc
eGambitUnsafe.AI_Score_95%
FortinetW32/Waski.C!tr
AVGWin32:Malware-gen
Cybereasonmalicious.444692
AvastWin32:Malware-gen
MaxSecureTrojan.Upatre.Gen

How to remove Mal/Generic-S + Mal/Upatre-AS?

Mal/Generic-S + Mal/Upatre-AS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment