Trojan

Trojan.Win32.Hesv.fvsb removal tips

Malware Removal

The Trojan.Win32.Hesv.fvsb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Hesv.fvsb virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Hesv.fvsb?


File Info:

name: B3642E13D510C71753D8.mlw
path: /opt/CAPEv2/storage/binaries/8ed8de5f985d3946f6d4946f64e85b9eeaa76f4fd2e677fc052520ebfb1a7a86
crc32: 6503A2A0
md5: b3642e13d510c71753d84f2028b2a63c
sha1: 96ac70e122e6cdb1848173fff9a439b85850fbb3
sha256: 8ed8de5f985d3946f6d4946f64e85b9eeaa76f4fd2e677fc052520ebfb1a7a86
sha512: 81ee0583b67c7074b2fefe8aa4b39c695e1f94f6f321b4b542a912585ed47ce6a4ab4121b74d62db6db78117f720c2570ce438e1d0c27f2a50ee0ad9f17d5ed1
ssdeep: 3072:d630thKdTAodJza64TRnltulOuQuT1XwQVXz5uU0OGsLo3XEqfXz:d0ZETpYzAjLsLcf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12354F60373EA941EE8B277B05EFAD355C637BD299633C21F3284195F5DA1A405E223B2
sha3_384: 9ca9867530b4e22ec3570986007e2dd62d5f69f60b201fa25865f0e8c42cf19506831978333c67200c9789c6d8f646ac
ep_bytes: 60be001047008dbe0000f9ff57eb0b90
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Trojan.Win32.Hesv.fvsb also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Autoit.mBpQ
MicroWorld-eScanGen:Variant.Zusy.411698
ClamAVWin.Malware.Zusy-9956636-0
FireEyeGeneric.mg.b3642e13d510c717
ALYacGen:Variant.Zusy.411698
CylanceUnsafe
VIPREGen:Variant.Zusy.411698
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/Hesv.332d49c7
K7GWTrojan ( 700000111 )
Cybereasonmalicious.3d510c
BaiduWin32.Trojan.AutoIt.a
CyrenW32/S-79628cd6!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Hesv.fvsb
BitDefenderGen:Variant.Zusy.411698
AvastWin32:Malware-gen
TencentWin32.Trojan.Hesv.Xdkl
Ad-AwareGen:Variant.Zusy.411698
SophosML/PE-A
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.Hesv.Win32.5585
TrendMicroTROJ_GEN.R002C0WK422
McAfee-GW-EditionBehavesLike.Win32.BadFile.dt
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.411698 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.1K78EN9
JiangminTrojan.Hesv.dnb
AviraHEUR/AGEN.1214975
Antiy-AVLTrojan/Generic.ASMalwS.3C54
ArcabitTrojan.Zusy.D64832
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3HEUR/Fakon.mwf.X1381
Acronissuspicious
McAfeeArtemis!B3642E13D510
MAXmalware (ai score=81)
TrendMicro-HouseCallTROJ_GEN.R002C0WK422
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
IkarusTrojan-Downloader.Win32.Genome
MaxSecureTrojan.Malware.184646616.susgen
FortinetW32/ULPM.16C0!tr
BitDefenderThetaGen:NN.ZexaF.34754.rm0@aeE6qtli
AVGWin32:Malware-gen

How to remove Trojan.Win32.Hesv.fvsb?

Trojan.Win32.Hesv.fvsb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment