Trojan

About “Trojan.UPMF.S32620305” infection

Malware Removal

The Trojan.UPMF.S32620305 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.UPMF.S32620305 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Binary file triggered YARA rule
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.UPMF.S32620305?


File Info:

name: 93568170A0D724B64813.mlw
path: /opt/CAPEv2/storage/binaries/00efd0afea8e1f375eae9b05d995600cfd8238511f4d6a0b7881e0db9d7dedba
crc32: 780972B7
md5: 93568170a0d724b64813fcbf9a1aad2a
sha1: ea88c0ce7113aaaa45b4bdb7b6ca638a19d05763
sha256: 00efd0afea8e1f375eae9b05d995600cfd8238511f4d6a0b7881e0db9d7dedba
sha512: 9312b676408aefe277f85717a11a2d84ada1eb1af1e4e75bcd63184daff0bbb2f224df3d9d4f6638e324746243bdb6ed5c4bd6c0c42ec191628206795f15d07d
ssdeep: 768:xW9+F8BPtElggggggLvggggggggUaocdF+qqPbNMugJI/xZ9dHtTFmd1MVZyg6N2:ekoqzqTNMDSpZ9fTKMTVe2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1555339386AD51572E37BCEB6C5F251CAB969BC1339035C0E40B6F3440AB3BD2ADA151E
sha3_384: af247258c9276fe359205dfdd1dfda6faa0b67522295aaa6bd1340ace9b824754bc297c847e654f15abb5a1cef5bb4d9
ep_bytes: 558bec6aff68b8324000680010400064
timestamp: 1992-05-31 15:52:29

Version Info:

CompanyName: Juice
FileDescription: Juice proged
FileVersion: Version 2.1.1
InternalName: Juice
LegalCopyright: Copyright by Sego©
OriginalFilename: iJuice
Translation: 0x0409 0x04e3

Trojan.UPMF.S32620305 also known as:

BkavW32.FamVT.GeND.Trojan
LionicTrojan.Win32.Crypt.m2KH
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.93568170a0d724b6
CAT-QuickHealTrojan.UPMF.S32620305
SkyhighBehavesLike.Win32.Generic.kt
McAfeeDownloader-FAGS!93568170A0D7
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Cryptodef.Win32.2887
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0052964f1 )
AlibabaRansom:Win32/Cryptodef.5b44137c
K7GWTrojan ( 0052964f1 )
BaiduWin32.Trojan-Downloader.Waski.a
VirITTrojan.Win32.Panda.LFU
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
TrendMicro-HouseCallTROJ_UPATRE.SMX2
Paloaltogeneric.ml
ClamAVWin.Malware.Upatre-9848438-0
KasperskyTrojan-Ransom.Win32.Cryptodef.zv
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.Cryptodef.ddoxyv
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Downloader.zv
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureTrojan.TR/Kuluoz.lrse
DrWebTrojan.PWS.Panda.7586
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_UPATRE.SMX2
Trapminemalicious.high.ml.score
SophosTroj/Zbot-PQI
IkarusTrojan.Win32.Bublik
JiangminTrojan/Cryptodef.az
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraTR/Kuluoz.lrse
VaristW32/Upatre.OI.gen!Eldorado
Antiy-AVLVirus/Win32.Expiro.imp
KingsoftWin32.HeurC.KVM007.a
MicrosoftTrojan:Win32/Zbot.svfs!MTB
XcitiumTrojWare.Win32.TrojanDownloader.Waski.DA@5iyglc
ArcabitTrojan.Ppatre.Gen.1
ZoneAlarmTrojan-Ransom.Win32.Cryptodef.zv
GDataWin32.Trojan-Downloader.Upatre.BK
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Cryptodef.R415348
Acronissuspicious
VBA32TrojanRansom.Cryptodef
ALYacTrojan.Ppatre.Gen.1
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.25356
RisingDownloader.Waski!1.A489 (CLASSIC)
MAXmalware (ai score=85)
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr.dldr
BitDefenderThetaGen:NN.ZexaF.36804.dq3@amcHZdhi
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudRansomware:Win/Waski.A

How to remove Trojan.UPMF.S32620305?

Trojan.UPMF.S32620305 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment