Trojan

Trojan-Downloader.Win32.Upatre.jcfl information

Malware Removal

The Trojan-Downloader.Win32.Upatre.jcfl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.jcfl virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Upatre.jcfl?


File Info:

name: 80306EFED09F144844B4.mlw
path: /opt/CAPEv2/storage/binaries/cd1b7d2b45b5229ac345fd3a457f6f5187012e0154b8a8ad04a21fe269072f15
crc32: 3D525FB1
md5: 80306efed09f144844b459a5a242602a
sha1: 2d42305ce1d7c1c293e35bd513a39744c8bc13eb
sha256: cd1b7d2b45b5229ac345fd3a457f6f5187012e0154b8a8ad04a21fe269072f15
sha512: b0ef48b7758ed95f1724c239aebb70a1f5845d86742e5e457841e6698380529b7a77af25e610a5523fec5bbb0ac395013b2e105f8ff4d5c36462c38d5743fe25
ssdeep: 196608:Xp+Y6nJiP6iW+WjXje4+eXZgF6+Fnjs3wvsGPfnG:XMnoPPW7ve5eXZgJvsAf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D763337926211C5E0F9D83A462BBDEDB1F5077D990268B834D6EDC51E318E9F213A83
sha3_384: 6672820448fcec0d5427f4049dd8cee37f6ae4e876933c248aea610c8d251ff4a00bff4c08ffb4b0224e41275b773ab1
ep_bytes: 6830797202e84a7f1600e9283dfcffc1
timestamp: 2013-06-15 16:44:28

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Upatre.jcfl also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Upatre.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38845482
FireEyeGeneric.mg.80306efed09f1448
ALYacTrojan.GenericKD.38845482
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojanDownloader:Win32/Upatre.9f8d2b29
K7GWTrojan ( 005265fb1 )
K7AntiVirusTrojan ( 005265fb1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.SN
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Upatre.jcfl
BitDefenderTrojan.GenericKD.38845482
AvastWin32:Trojan-gen
TencentWin32.Trojan-downloader.Upatre.Dwsm
Ad-AwareTrojan.GenericKD.38845482
SophosMal/VMProtBad-A
ZillyaDownloader.Upatre.Win32.70325
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftTrojan.GenericKD.38845482 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.38845482
AviraHEUR/AGEN.1210643
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.351EB14
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D250BC2A
ViRobotTrojan.Win32.Z.Vmprotect.7649280
MicrosoftTrojan:Win32/Tnega!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.RL_ConvertAd.R362678
Acronissuspicious
McAfeeArtemis!80306EFED09F
VBA32TScope.Malware-Cryptor.SB
TrendMicro-HouseCallTROJ_GEN.R002H07B122
RisingDownloader.Upatre!8.B5 (CLOUD)
YandexTrojan.GenAsa!F7GxKnMDlbs
IkarusTrojan.Win32.VMProtect
eGambitUnsafe.AI_Score_96%
FortinetRiskware/Application
BitDefenderThetaGen:NN.ZexaF.34212.@xW@am5Suom
AVGWin32:Trojan-gen
Cybereasonmalicious.ce1d7c
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.139171778.susgen

How to remove Trojan-Downloader.Win32.Upatre.jcfl?

Trojan-Downloader.Win32.Upatre.jcfl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment