Trojan

Should I remove “Trojan-Downloader.Win32.Upatre.jind”?

Malware Removal

The Trojan-Downloader.Win32.Upatre.jind is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.jind virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Trojan-Downloader.Win32.Upatre.jind?


File Info:

name: A896D6AB6C38D1666B22.mlw
path: /opt/CAPEv2/storage/binaries/3916e29b02271de2da96ed7b42cd72b140d5c23ee47b555e6627efdc5d43b7a2
crc32: ACF17830
md5: a896d6ab6c38d1666b22992b61731a5a
sha1: a98f80f3057de6c3b03837cb14e2e6f452581017
sha256: 3916e29b02271de2da96ed7b42cd72b140d5c23ee47b555e6627efdc5d43b7a2
sha512: edd71e70c3a79421b68c2832aba834d78f2fee9d5a70072d0ecb420a19ac2c161d6b560caac0f9a4dcefaa73f9d8fba2123cd868cb238ae6410247bcdcf1ce58
ssdeep: 49152:6N8brf7cL4uJPah6diKUVPp4TUCg322oaYPYgY6W9r/im46Go12LCaVJhXAQq5:Vb7QL3JPvdikIXIYT6W4mXGo12+aVJhU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T117D533EB7E2623F5C0C052345A2F3DE5268D0C7189D5AD3B6BE77659C33F09B69088A1
sha3_384: 3617fcf857d4035e68038735a9aa62f2cd53a7735e13886abd11f9ab0c7bdc861b083fdb179dfef72953b293e50eb2d1
ep_bytes: 60c744241cad8fba29684236f9a5e92a
timestamp: 2022-10-17 14:24:59

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Upatre.jind also known as:

BkavW32.AIDetect.malware2
FireEyeGeneric.mg.a896d6ab6c38d166
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004b942f1 )
K7GWAdware ( 004b942f1 )
Cybereasonmalicious.3057de
BitDefenderThetaGen:NN.ZexaF.34754.SAW@aa98vGob
CyrenW32/Upatre.OP.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.Injector.D potentially unwanted
APEXMalicious
KasperskyTrojan-Downloader.Win32.Upatre.jind
CynetMalicious (score: 100)
RisingTrojan.Generic@AI.99 (RDML:Kb5NvbCNfa84l1S8V0HzVg)
ComodoTrojWare.Win32.Trojan.XPack.~gen1@1rwlif
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vc
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
AviraTR/Dldr.Upatre.ojemt
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Generic.C646661
VBA32BScope.Trojan.Download
MalwarebytesTrojan.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002H07JS22
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/FlyStudio
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan-Downloader.Win32.Upatre.jind?

Trojan-Downloader.Win32.Upatre.jind removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment