Trojan

What is “Trojan.Win32.Hesv.fhcn”?

Malware Removal

The Trojan.Win32.Hesv.fhcn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Hesv.fhcn virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Trojan.Win32.Hesv.fhcn?


File Info:

name: CF0F2ACB7EAC4A65A03C.mlw
path: /opt/CAPEv2/storage/binaries/42902a8e4ea92eea2026f2e6ab6affc3781aaf959ce9ee8e4827276d411d7d80
crc32: 7E2D83FB
md5: cf0f2acb7eac4a65a03c1a99bf53a581
sha1: 4f7a5d1e247df15fe1b3b40e3d035677c2b911a4
sha256: 42902a8e4ea92eea2026f2e6ab6affc3781aaf959ce9ee8e4827276d411d7d80
sha512: 851668973e8e3ae214c5f8a2430ece4847ccc640da082854bf70c1a6341e88d4ecf1c8bbad6fada80319e58ba2fe4b518702746c5d0561dd35ddefd59f8b3c81
ssdeep: 12288:gzy6rRxEqbpnfkjuVtPuVcG6YO/uV1ObuVtEnvysf1Q1TkAQTutHHHC:z6rT5bp8iVtGVcG9pV1OqVtEnSQT0ni
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D3C40201FFC640F6D4400B3064AFB235D63EFF152971A6D8DB9A7C2A68BA542F01DB66
sha3_384: 36636d05ead3a71406d2b94384149d026a76d6ffa80fb83c9e8dc8e18fea94df66a9445f05645fda15385d98c2c8e61a
ep_bytes: e82f2b000050e83f3101000000000090
timestamp: 2007-05-22 04:59:14

Version Info:

0: [No Data]

Trojan.Win32.Hesv.fhcn also known as:

BkavW32.AIDetectMalware
LionicVirus.BAT.Agent.mzQk
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Trojan.Generic.1624094
ClamAVWin.Trojan.Pcclient-4245
FireEyeGeneric.mg.cf0f2acb7eac4a65
CAT-QuickHealTrojan.Orsam.A4
McAfeeArtemis!CF0F2ACB7EAC
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Hesv.42a16fe4
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b7eac4
VirITBackdoor.Win32.PcClient.DTRV
CyrenW32/Imaut.A.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Agent.TRF
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Hesv.fhcn
BitDefenderDropped:Trojan.Generic.1624094
NANO-AntivirusTrojan.Win32.PcClient.dgwtmn
ViRobotBackdoor.Win32.PcClient.584516
AvastWin32:Malware-gen
TencentWin32.Virus.Sola.Wmhl
EmsisoftDropped:Trojan.Generic.1624094 (B)
BaiduWin32.Trojan.Generic.u
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.PcClient.3131
VIPREDropped:Trojan.Generic.1624094
TrendMicroTROJ_GEN.R002C0OEQ22
McAfee-GW-EditionGeneric BackDoor.agg
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
GDataDropped:Trojan.Generic.1624094 (2x)
JiangminTrojanDropper.Agent.acdm
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.AGeneric
XcitiumBackdoor.Win32.PcClient.d21@4gvmfr
ArcabitTrojan.Generic.D18C81E [many]
SUPERAntiSpywareTrojan.Agent/Gen-PCClient
ZoneAlarmTrojan.Win32.Hesv.fhcn
MicrosoftTrojan:Win32/Olsa!rfn
AhnLab-V3Dropper/PcClient.Gen
Acronissuspicious
VBA32Trojan.Msht
ALYacDropped:Trojan.Generic.1624094
MAXmalware (ai score=83)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0OEQ22
RisingMalware.FakeDOC/ICON!1.9C3B (CLASSIC)
YandexBackdoor.PcClient!W7zsy3qaZ98
IkarusTrojan.SuspectCRC
FortinetW32/PcClient.FED!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Hesv.fhcn?

Trojan.Win32.Hesv.fhcn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment