Hm, I downloaded the latest TrojanSimulator and I got this result:
C:\zz\Debug>ashcmd /t=a /a /_ c:\a
c:\a\Readme.txt OK
c:\a\TrojanSimulator.exe OK
c:\a\TSServ.exe\[UPX] OK
c:\a\TSServ.exe OK
As you can see, TrojanSimulator.exe is not packed with UPX (it isn't, really) but TSServ.exe is.
We know, winexec compressors, are used in mostly trojans (mainly upx/aspack/...). We've improved AsPack unpacker (for unknown versions, more robust generally) and it'll be available (sometime) in v4.2. I hope I find time for UPX improve as well.