Trojan

Should I remove “Trojan-Downloader.Win32.Upatre.jchw”?

Malware Removal

The Trojan-Downloader.Win32.Upatre.jchw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.jchw virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Trojan-Downloader.Win32.Upatre.jchw?


File Info:

name: 2605A9708A93CB928B79.mlw
path: /opt/CAPEv2/storage/binaries/70bcc9c5099ba97732ab71c55aba2df5d24158cffa5d52c339535715545f464c
crc32: B48A7410
md5: 2605a9708a93cb928b798c44daa7e609
sha1: 9f1f83c821e85b55f9a08e0c4fe5c0a7bd405004
sha256: 70bcc9c5099ba97732ab71c55aba2df5d24158cffa5d52c339535715545f464c
sha512: b247a7a347c524ecdf9dcbb3074a2487c7ddd0d84cf68bd8f6f3e030304ba1390268d71f1bcbbfd8ffd109bad70d271eef4997d3f908671d2c40d0a8b78f6300
ssdeep: 98304:JZgexBVitIDFGcPdcfw5AMSggnHpZ7l4KlJXMj+6KqZKU1ZwvsWpzc2+XFqfFCnL:pj2IwwdieBSggPl4yXMj+61ZKGZhWpzk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C463302A9D259F2D6151E75454E7B912C3D3E602B20DAFFD3EC9E2EA4701D0EB36B12
sha3_384: 1da15b0d797a8e39ef2ad55e0dc01e8fea230a4cdd05d60762280dc781fa73aa1a9b489e176aa8dc9474621bfa53a5e8
ep_bytes: e864040000e988feffff3b0d68e64300
timestamp: 2021-06-11 09:16:47

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Upatre.jchw also known as:

LionicTrojan.Win32.NanoBot.trQD
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop19.27719
CynetMalicious (score: 100)
FireEyeGeneric.mg.2605a9708a93cb92
McAfeeArtemis!2605A9708A93
CylanceUnsafe
SangforTrojan.Win32.Upatre.jchv
K7AntiVirusTrojan ( 0057f8511 )
AlibabaPacked:Win32/VMProtect.37bd1854
K7GWTrojan ( 0057f8511 )
Cybereasonmalicious.821e85
BitDefenderThetaGen:NN.ZexaF.34212.@BW@aqImUbli
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Packed.VMProtect.SN
TrendMicro-HouseCallTROJ_GEN.R002H09B622
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Upatre.jchw
BitDefenderTrojan.GenericKD.48277327
MicroWorld-eScanTrojan.GenericKD.48277327
AvastWin32:Evo-gen [Susp]
TencentWin32.Trojan-downloader.Upatre.Hoen
Ad-AwareTrojan.GenericKD.48277327
TrendMicroTROJ_GEN.R002C0RB622
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.GenericKD.48277327 (B)
IkarusTrojan-Dropper.Win32.Small
GDataWin32.Trojan.Agent.2GQXUI
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.3522C1D
GridinsoftRansom.Win32.Sabsik.sa
ZoneAlarmTrojan-Downloader.Win32.Upatre.jchw
MicrosoftTrojan:Win32/Tiggre!rfn
ALYacTrojan.GenericKD.48277327
VBA32TScope.Malware-Cryptor.SB
APEXMalicious
RisingDownloader.Upatre!8.B5 (CLOUD)
YandexTrojan.Igent.bXrnd7.16
SentinelOneStatic AI – Malicious SFX
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Susp]
PandaTrj/CI.A

How to remove Trojan-Downloader.Win32.Upatre.jchw?

Trojan-Downloader.Win32.Upatre.jchw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment