Trojan

Trojan-Downloader.Win32.Agent.hehd removal guide

Malware Removal

The Trojan-Downloader.Win32.Agent.hehd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Agent.hehd virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan-Downloader.Win32.Agent.hehd?


File Info:

name: E60656871B569A40CEAF.mlw
path: /opt/CAPEv2/storage/binaries/dd39880dc5421b8ed81e6f46e9ac13347b3b5e797a3733e6179d8d3d91c6566a
crc32: 616188B6
md5: e60656871b569a40ceaffa8a88a1437d
sha1: 71f8936c4388e9ad8efc47cd442f32b6aa5d5b70
sha256: dd39880dc5421b8ed81e6f46e9ac13347b3b5e797a3733e6179d8d3d91c6566a
sha512: e50173ad0d70c61717b6fc88796b1a1487a2562cee96f949c50d3a34499980ae6a9682ce9ede6ea564591429d83bd9cc1378d5d4a69c803b41f2d779967bb681
ssdeep: 192:ikJwHP34EuCo5IE3BQ4VmK7AUbvxf4VXGn/OPPDPPVnJTLKNwwwwwwwwwwwwwwwt:ikO5SQ49vxWXGn/Oz3TVfRN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16A92C6026200499AF53F8FF2147EDB5168D9710B11AB2ACFB9D14F372662302576E37D
sha3_384: 3afa823e7479916e55745717e4bf4639c0a40a56acb35b2f4278bab60c9b1d25b3b1f31ff648a32ff7043d3a7bc922ba
ep_bytes: 558bec83c4dc6a00ff1520204000508d
timestamp: 2013-07-19 03:19:22

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Agent.hehd also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Upatre.Gen.3
FireEyeGeneric.mg.e60656871b569a40
CAT-QuickHealTrojanDownloader.Upatre.V4
McAfeeDownloader-FSH!E60656871B56
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0040f7f11 )
BitDefenderTrojan.Upatre.Gen.3
K7GWTrojan-Downloader ( 0040f7f11 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34212.bq1@aGUMn@pi
VirITTrojan.Win32.Generic.CBGV
CyrenW32/Trojan.HXHI-8341
SymantecDownloader.Upatre!gen5
ESET-NOD32Win32/TrojanDownloader.Waski.B
BaiduWin32.Trojan-Downloader.Waski.a
APEXMalicious
ClamAVWin.Trojan.Agent-1328090
KasperskyTrojan-Downloader.Win32.Agent.hehd
NANO-AntivirusTrojan.Win32.Agent.cwvzoe
RisingDownloader.Waski!8.184 (RDMK:cmRtazoHg4Bms82jicUqftYfADSA)
Ad-AwareTrojan.Upatre.Gen.3
SophosML/PE-A + Troj/Upatre-BE
ComodoTrojWare.Win32.TrojanDownloader.Agent.HE@59ncuy
DrWebTrojan.DownLoad3.32696
ZillyaDownloader.Agent.Win32.185843
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.lm
EmsisoftTrojan.Upatre.Gen.3 (B)
IkarusTrojan-Downloader.Win32.Upatre
GDataTrojan.Upatre.Gen.3
JiangminTrojanDownloader.Agent.enea
AviraTR/Yarwi.clem
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.971479
SUPERAntiSpywareTrojan.Agent/Gen-Jorik
MicrosoftTrojanDownloader:Win32/Upatre.AA
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R101794
Acronissuspicious
VBA32TrojanDownloader.Agent
ALYacTrojan.Upatre.Gen.3
MalwarebytesTrojan.Email.FakeDoc
PandaGeneric Malware
TrendMicro-HouseCallTROJ_UPATRE.SMJ9
TencentMalware.Win32.Gencirc.11495074
YandexTrojan.DL.Agent!NfW9bb8gmRA
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.OOU!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.71b569
AvastWin32:Trojan-gen

How to remove Trojan-Downloader.Win32.Agent.hehd?

Trojan-Downloader.Win32.Agent.hehd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment