Trojan

Trojan.Win32.Hesv.cqza information

Malware Removal

The Trojan.Win32.Hesv.cqza is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Hesv.cqza virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Win32.Hesv.cqza?


File Info:

name: 78F9C96E94D9FE122565.mlw
path: /opt/CAPEv2/storage/binaries/0e707c5b7fd97050e0bf6e24cf5dc7caff87ba90ca3a19377109c48835b6b97f
crc32: 2FD056F8
md5: 78f9c96e94d9fe122565f91b38b59515
sha1: cb200874d8fab28c5eac9224ec57b3e17a1b6ee3
sha256: 0e707c5b7fd97050e0bf6e24cf5dc7caff87ba90ca3a19377109c48835b6b97f
sha512: 9939f21402ed6499eeaa9a2c92c78271177d74b24c9276c3f02fd3eecc20be831301e25a2797717a2562a11b4025c0ea4ee0d1d4ce98be89b3449e51b05fe723
ssdeep: 6144:db0w8DFe0qip4r1XNOmNBLxAG7H59R7g0fY4rGK/fObT/bGijVq1Wzr/+mNGXnFT:db38DFe0qip4rZNOm3FAG7H59R7g0fY4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C34A712BA11F41EE59398F41A399397783D2CBB26A0BC4777827F242971197B8B071F
sha3_384: 2870083a26b6c0643675ed81311a8a59174e99a2525fa4f9c2e23b1d6e7edecd305b6817279c9dad65fbece88ab1d1b7
ep_bytes: 68ac404000e8eeffffff000048000000
timestamp: 2011-12-24 18:51:58

Version Info:

FileVersion: 1.00
Translation: 0x0409 0x04b0

Trojan.Win32.Hesv.cqza also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.2644
ClamAVWin.Trojan.VB-73739
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.df
Cylanceunsafe
ZillyaTrojan.Hesv.Win32.13612
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.6619b160
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.e94d9f
BitDefenderThetaGen:NN.ZevbaF.36250.pm0@aah4PEhi
VirITTrojan.Win32.Zyx.GV
CyrenW32/Vobfus.AA.gen!Eldorado
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.AQE
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Hesv.cqza
BitDefenderGen:Variant.Barys.2644
NANO-AntivirusTrojan.Win32.WBNA.cqkxnq
ViRobotTrojan.Win32.A.Diple.249856.B
AvastWin32:VB-AALL [Trj]
TencentTrojan.Win32.FakeFolder.pid
TACHYONTrojan/W32.Hesv.249856
EmsisoftGen:Variant.Barys.2644 (B)
BaiduWin32.Worm.Autorun.l
F-SecureTrojan.TR/Kazy.502561
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Barys.2644
TrendMicroWORM_VOBFUS.SMAB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
FireEyeGeneric.mg.78f9c96e94d9fe12
SophosW32/SillyFDC-GQ
SentinelOneStatic AI – Suspicious PE
AviraTR/Kazy.502561
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.CF
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Barys.DA54
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmTrojan.Win32.Hesv.cqza
GDataGen:Variant.Barys.2644
GoogleDetected
AhnLab-V3Trojan/Win32.Menti.R19084
VBA32BScope.Trojan.Diple
MAXmalware (ai score=84)
MalwarebytesMalware.AI.3441909735
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!Wa92FI4OeAQ
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
AVGWin32:VB-AALL [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Hesv.cqza?

Trojan.Win32.Hesv.cqza removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment