Trojan

Should I remove “Trojan-Downloader.Win32.Agent.hefq”?

Malware Removal

The Trojan-Downloader.Win32.Agent.hefq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Agent.hefq virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Uses csc.exe C# compiler to build and execute code
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Downloader.Win32.Agent.hefq?


File Info:

name: B02B55F132C6A4528F57.mlw
path: /opt/CAPEv2/storage/binaries/1545d1b794566ee4d4b1541b778558db0a4e1d92c95b1662f4ed70cf719f28df
crc32: AB6B278A
md5: b02b55f132c6a4528f57bd3bbdb9b02e
sha1: 0ded5326752b185fcf83b7d905208e3cb0f513b1
sha256: 1545d1b794566ee4d4b1541b778558db0a4e1d92c95b1662f4ed70cf719f28df
sha512: b9d241556c74783ca08fa6a3760bd58036329066355c2f2525388fe9d50453819e923dbd0705575e36c6fd3fe98efac496bdd12c7c92968b4c55d13fd640dd1f
ssdeep: 192:dIXdC1/mEtAExeCGTK5zTCLjLYyL+K+JbE2JiupC1tS21QCvpCRfJj:ONLEQCsYOcym4SC0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B92732172D41769E7B7BFB238BFD2A812603C6F3728560D2F813F464891B1179AD789
sha3_384: 3988f446e8520e8bb0e6e7004b3e7f09969d958ec8a63b1357a4eadbeae34b7f0762fdf3111e83414a9701b8224da718
ep_bytes: 558bec83c4b48d4db451ff151c204000
timestamp: 2013-07-12 05:40:02

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Agent.hefq also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanTrojan.GenericKD.1631710
ClamAVWin.Trojan.Zbot-64721
FireEyeGeneric.mg.b02b55f132c6a452
CAT-QuickHealTrojanDownloader.Upatre.A4
SkyhighBehavesLike.Win32.Downloader.lm
McAfeeDownloader-FSH
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Agent.Win32.225510
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0040f7f11 )
K7GWTrojan-Downloader ( 0040f7f11 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D18E5DE
BitDefenderThetaGen:NN.ZexaF.36792.bq1@a0C40xhi
SymantecTrojan.Zbot
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Waski.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Agent.hefq
BitDefenderTrojan.GenericKD.1631710
NANO-AntivirusTrojan.Win32.DownLoad3.cwcgwz
AvastWin32:Agent-AUID [Trj]
TencentMalware.Win32.Gencirc.10bf28ed
SophosTroj/Upatre-AL
F-SecureTrojan.TR/Yarwi.hotwk
BaiduWin32.Trojan-Downloader.Waski.a
VIPRETrojan.GenericKD.1631710
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.1631710 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Agent.epea
GoogleDetected
AviraTR/Yarwi.hotwk
MAXmalware (ai score=83)
Antiy-AVLTrojan[Downloader]/Win32.Agent
Kingsoftmalware.kb.a.998
XcitiumTrojWare.Win32.Bublik.CEZE@595kvx
MicrosoftTrojan:Win32/Trickbot.GML!MTB
ZoneAlarmTrojan-Downloader.Win32.Agent.hefq
GDataTrojan.GenericKD.1631710
VaristW32/Trojan.QTEC-3681
AhnLab-V3Downloader/Win32.Upatre.C291285
ALYacTrojan.GenericKD.1631710
VBA32TrojanDownloader.Agent
Cylanceunsafe
PandaGeneric Malware
ZonerTrojan.Win32.22294
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Upatre!8.B5 (TFE:2:yA9vyp2H25H)
YandexTrojan.DL.Agent!oPrSMEZ2Nxs
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.OOU!tr
AVGWin32:Agent-AUID [Trj]
Cybereasonmalicious.6752b1
DeepInstinctMALICIOUS

How to remove Trojan-Downloader.Win32.Agent.hefq?

Trojan-Downloader.Win32.Agent.hefq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment