Trojan

Should I remove “Trojan.Win32.Hesv.fwsk”?

Malware Removal

The Trojan.Win32.Hesv.fwsk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Hesv.fwsk virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Hesv.fwsk?


File Info:

name: FB1D6009462C40129DA4.mlw
path: /opt/CAPEv2/storage/binaries/1d0d98c77ca8cd5e998080e444e85252cf06c55ce5e0a7dc77bd1d31efa559fd
crc32: 3C806E3F
md5: fb1d6009462c40129da4209bd07f1ffe
sha1: 38b48cb308cc20e0dc10a84687f1ed5457e133fc
sha256: 1d0d98c77ca8cd5e998080e444e85252cf06c55ce5e0a7dc77bd1d31efa559fd
sha512: 713e195fb3459867c8b463b7d6f2c8749fb44164b58f7af0cfbea59d479d645f2f69e47875754610635fc007d6c29e81b97c9dafe55625569a37c503a9d34f8f
ssdeep: 3072:y630thKdTAodJza64TRnltulOuQuT1XwQVXz5u8EOGsLo3XEqfXX:y0ZETpYzADLsLcL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C154F60373EA941EE8B277B05EFAD355C637BD299233C21F3284195F5DA1A405E223B2
sha3_384: bc965746345ce303aa3fd24000e566b0353652cd89b4922cc34766c95c0f5079389ef569dd1a73303035e9730e7f52b1
ep_bytes: 60be001047008dbe0000f9ff57eb0b90
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Trojan.Win32.Hesv.fwsk also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Strictor.267438
ClamAVWin.Malware.Zusy-9956636-0
FireEyeGeneric.mg.fb1d6009462c4012
McAfeeArtemis!FB1D6009462C
Cylanceunsafe
VIPREGen:Variant.Strictor.267438
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36196.rm0@amLoo5pi
CyrenW32/S-79628cd6!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Hesv.fwsk
BitDefenderGen:Variant.Strictor.267438
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10be9d88
Ad-AwareGen:Variant.Strictor.267438
EmsisoftGen:Variant.Strictor.267438 (B)
F-SecureHeuristic.HEUR/AGEN.1363450
BaiduWin32.Trojan.AutoIt.a
ZillyaTrojan.Hesv.Win32.5585
McAfee-GW-EditionBehavesLike.Win32.RealProtect.dt
Trapminemalicious.moderate.ml.score
SophosML/PE-A
IkarusTrojan.Win32.Autoit
GDataWin32.Trojan.PSE.1K78EN9
JiangminTrojan.Hesv.dnb
AviraHEUR/AGEN.1363450
Antiy-AVLTrojan/Win32.TSGeneric
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Strictor.D414AE
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3HEUR/Fakon.mwf.X1381
ALYacGen:Variant.Strictor.267438
MAXmalware (ai score=82)
MalwarebytesAutoIt.Trojan.MalPack.DDS
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.77298014.susgen
FortinetW32/ULPM.16C0!tr
AVGWin32:Malware-gen
Cybereasonmalicious.9462c4
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Hesv.fwsk?

Trojan.Win32.Hesv.fwsk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment