Trojan

What is “Trojan-Downloader.Win32.Upatre.jfqz”?

Malware Removal

The Trojan-Downloader.Win32.Upatre.jfqz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.jfqz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity

How to determine Trojan-Downloader.Win32.Upatre.jfqz?


File Info:

name: 5B953EE76F004EE59A86.mlw
path: /opt/CAPEv2/storage/binaries/54407755b64c289cad9e7beed1ddcb554b38aabf69ea1fc05f5badd2da923a95
crc32: 730B0201
md5: 5b953ee76f004ee59a8665d9e9288a46
sha1: 89a3425533a5d101228da68d2a19a3fd6efdf30d
sha256: 54407755b64c289cad9e7beed1ddcb554b38aabf69ea1fc05f5badd2da923a95
sha512: 3a78560904f5007d2213161bf83aa70dc0154c3c574eec3e0df7d76d039fbb07751755bf4d1de72d6055592108f2adf10b7ae39f6c09a44a0403c97a0037640b
ssdeep: 196608:sb48vH/1ykrsIAIoGu8hjsy6gA7TJEQWGUnBgCMYXPdjYcA:+XvNykD/PsyJQLWCuXVc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14186331E09295BDEC60658B8D64ED4DE9278E4EB3482C5C537BCA3D6270AFE33D48643
sha3_384: c328fba1bbdb93e7799266426f7ae7f57c0a6c00e3696d8dafc20ce6a176834d450a031bb3b6aa33060a4006e1e43b31
ep_bytes: 9c880c24c7042480ac97979c9ce97071
timestamp: 2022-04-19 21:30:25

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Upatre.jfqz also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.5b953ee76f004ee5
McAfeeArtemis!5B953EE76F00
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004b8e1b1 )
AlibabaPacked:Win32/Vemply.0c598309
K7GWAdware ( 004b8e1b1 )
Cybereasonmalicious.533a5d
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.VMProtect.ABO
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Upatre.jfqz
AvastWin32:DropperX-gen [Drp]
SophosMal/VMProtBad-A
ComodoTrojWare.Win32.Agent.ISVQ@5mbonp
F-SecureTrojan.TR/Black.Gen2
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Spy.KrBanker.X831V1
AviraTR/Black.Gen2
ZoneAlarmTrojan-Downloader.Win32.Upatre.jfqz
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Trojan-gen.C4570936
BitDefenderThetaGen:NN.ZexaF.34742.@BW@aa0IMXob
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R002H07FR22
RisingTrojan.Generic@AI.97 (RDML:NULhZWSmvreiN3vmDEPzqg)
FortinetW32/PossibleThreat
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan-Downloader.Win32.Upatre.jfqz?

Trojan-Downloader.Win32.Upatre.jfqz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment