Trojan

Trojan-Downloader.Win32.Upatre.ihen removal guide

Malware Removal

The Trojan-Downloader.Win32.Upatre.ihen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.ihen virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity contains more than one unique useragent.
  • Anomalous binary characteristics

Related domains:

gg-clean.hk

How to determine Trojan-Downloader.Win32.Upatre.ihen?


File Info:

crc32: 98664F0A
md5: 5d31c6ab74d4b27dc040f3d3b450888b
name: kiskis.exe
sha1: c81dab4b19a3975dcba34ceac3cf69f42939076d
sha256: f3472708068d8cc5d0d112e6920ec42c8d09e07fc8fca1baf5c7084d2351b315
sha512: b56bd6ae4d7bf23c4ba9f453e3fb718eeb691ea70c03a38f52bb9bec37a25b8728f5411b56e2a338ee587a11fb790841e21159812d9668b02d4f192f327b7c22
ssdeep: 6144:gq9O+WqC9xdo4CpOTEYSFRzrbD052y9BNsm+DKSj:m9xefFxrbD08CBNQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0219 0x04e4

Trojan-Downloader.Win32.Upatre.ihen also known as:

DrWebTrojan.Siggen8.59199
MicroWorld-eScanTrojan.GenericKD.42076890
McAfeeRDN/Generic.grp
MalwarebytesTrojan.MalPack.GS
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.mCBm
SangforMalware
K7AntiVirusTrojan ( 003e58dd1 )
BitDefenderTrojan.GenericKD.42076890
K7GWTrojan ( 003e58dd1 )
Cybereasonmalicious.b19a39
BitDefenderThetaGen:NN.ZexaF.32519.ru0@a8858sl
F-ProtW32/Agent.BKJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Mikey-7426017-0
GDataTrojan.GenericKD.42076890
KasperskyTrojan-Downloader.Win32.Upatre.ihen
RisingTrojan.Kryptik!1.BFD8 (CLASSIC)
Ad-AwareTrojan.GenericKD.42076890
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Chapak.dorm
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.5d31c6ab74d4b27d
IkarusTrojan.Win32.Crypt
CyrenW32/Agent.BKJ.gen!Eldorado
JiangminTrojanDownloader.Bandit.ayy
WebrootW32.Adware.Gen
AviraTR/AD.Chapak.dorm
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2820ADA
ZoneAlarmTrojan-Downloader.Win32.Upatre.ihen
MicrosoftTrojan:Win32/GandCrypt.GE!MTB
AhnLab-V3Trojan/Win32.MalPe.R301700
Acronissuspicious
ALYacTrojan.GenericKD.42076890
MAXmalware (ai score=82)
VBA32Malware-Cryptor.Limpopo
CylanceUnsafe
ESET-NOD32a variant of Win32/Kryptik.GYYV
TrendMicro-HouseCallTROJ_GEN.R011C0DL319
SentinelOneDFI – Malicious PE
FortinetW32/Kryptik.GYYV!tr
AVGFileRepMalware
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Trojan.Generic

How to remove Trojan-Downloader.Win32.Upatre.ihen?

Trojan-Downloader.Win32.Upatre.ihen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment