Trojan

Trojan-Downloader.Win32.Upatre.iheb removal guide

Malware Removal

The Trojan-Downloader.Win32.Upatre.iheb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.iheb virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

gg-clean.hk
iplogger.org
apps.identrust.com

How to determine Trojan-Downloader.Win32.Upatre.iheb?


File Info:

crc32: B2AAFC97
md5: 373cc097d18b9a1ccbfca4947b0e8025
name: kiskis.exe
sha1: 0f724af3449a62ae9b060f1aedaa67f08ac88230
sha256: 20dbf121812a61abc13328fcb41fd485daa9e34d2e64353b5f7941911339bb50
sha512: 118a975ae4136b4f4d778cab6f45fe011090cd35dedfdb311d7da410affe18c8b034719e8ff5e1a7eee1358a26eeffa7cb7db86a5f972c3b2872a78ae906591f
ssdeep: 6144:cPOp1PkRiuhU8g1fzd2iqE335zvu4QZCRU3C2BAt2pO:jkRvhUpL2iq2QcR/2u1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0219 0x04e4

Trojan-Downloader.Win32.Upatre.iheb also known as:

MicroWorld-eScanTrojan.GenericKD.32771722
FireEyeGeneric.mg.373cc097d18b9a1c
McAfeeArtemis!373CC097D18B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Upatre.a!c
SangforMalware
K7AntiVirusTrojan ( 003c36381 )
BitDefenderTrojan.GenericKD.32771722
K7GWTrojan ( 003c36381 )
Cybereasonmalicious.3449a6
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.32515.ru0@a4argMi
CyrenW32/Trojan.UEZH-1609
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.32771722
KasperskyTrojan-Downloader.Win32.Upatre.iheb
RisingTrojan.Wacatac!8.10C01 (TFE:5:1n5cvSL0o1M)
Ad-AwareTrojan.GenericKD.32771722
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Chapak.doqy
DrWebTrojan.Siggen8.58983
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.dc
Trapminemalicious.moderate.ml.score
IkarusTrojan.Win32.Crypt
JiangminTrojanDownloader.Bandit.ayc
AviraTR/AD.Chapak.doqy
MAXmalware (ai score=87)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F40E8A
ZoneAlarmTrojan-Downloader.Win32.Upatre.iheb
MicrosoftTrojan:Win32/GandCrypt.GE!MTB
Acronissuspicious
VBA32Malware-Cryptor.Limpopo
ALYacTrojan.GenericKD.32771722
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.GYYQ
TrendMicro-HouseCallTROJ_GEN.R002H0CKU19
SentinelOneDFI – Malicious PE
FortinetW32/Kryptik.GYYN!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.298

How to remove Trojan-Downloader.Win32.Upatre.iheb?

Trojan-Downloader.Win32.Upatre.iheb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment