Trojan

Trojan.Win32.Regsup.cqih (file analysis)

Malware Removal

The Trojan.Win32.Regsup.cqih is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Regsup.cqih virus can do?

  • Unconventionial language used in binary resources: Russian
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Win32.Regsup.cqih?


File Info:

crc32: 9880A828
md5: 2babcfe9f79796823acb857c6a5117fc
name: 2BABCFE9F79796823ACB857C6A5117FC.mlw
sha1: 2c18c2e82c321d859860e044ea37c9f27263fa3e
sha256: 15ce13fcfcf33de1cc4c2325163b0b3e7057c282c4ba5644f5ceb3997e1167d5
sha512: d46a3efb37129c726f3948b80c50cde0810e448c2d49e18ffe12b2fd7ab94a0243d21ea955cc135c4b05674b5bf9756626edea76a512c40e9e6932e7d1c13031
ssdeep: 12288:wZpgaPpZ/t8s+CGv+srC/ReKDeKYbCxp863Atz5AC7/3qmkWH:wLgaPGDCUrrCpvjY+c6jCjqBWH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1995-2009 Trend Micro Incorporated. All rights reserved.
InternalName: Remove
FileVersion: 6.7.1.4
CompanyName: Copyright (CWx42b8fend Micro Inc.
1: Copyright (C) Trend Micro Inc.
ProductVersion: 9.6.3.6
Translation: 0x0409 0x04b0

Trojan.Win32.Regsup.cqih also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Nymaim.143
MicroWorld-eScanTrojan.Brsecmon.1
McAfeeRDN/GenDownloader.od
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005075571 )
BitDefenderTrojan.Brsecmon.1
K7GWTrojan ( 005075571 )
Cybereasonmalicious.9f7979
BitDefenderThetaGen:NN.ZexaF.34804.Nu0@aWdNkCac
SymantecPacked.Generic.546
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Regsup.cqih
AlibabaTrojan:Win32/Regsup.2e8c1aec
NANO-AntivirusTrojan.Win32.Nymaim.emddpr
AegisLabTrojan.Win32.Generic.4!c
RisingDownloader.Silcon!8.2D0A (CLOUD)
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-S
ComodoMalware@#yk86r258lxnp
F-SecureHeuristic.HEUR/AGEN.1117635
BaiduWin32.Trojan.Kryptik.bhw
ZillyaTrojan.Nymaim.Win32.1825
McAfee-GW-EditionRDN/GenDownloader.od
FireEyeGeneric.mg.2babcfe9f7979682
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE – Downloader
AviraHEUR/AGEN.1117635
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Nymaim
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanDownloader:Win32/Silcon!rfn
ArcabitTrojan.Brsecmon.1
ZoneAlarmTrojan.Win32.Regsup.cqih
GDataTrojan.Brsecmon.1
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1830279
VBA32Trojan.Nymaim
ALYacTrojan.Brsecmon.1
MalwarebytesTrojan.Nymaim.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.FPCR
TencentWin32.Trojan.Kryptik.Htwl
YandexTrojan.Kryptik!B9LwKvxQ6wQ
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_99%
FortinetW32/Nymaim.BA!tr
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Generic.HgIASOUA

How to remove Trojan.Win32.Regsup.cqih?

Trojan.Win32.Regsup.cqih removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment