Trojan

UDS:Trojan.Win32.Hesv.gfev malicious file

Malware Removal

The UDS:Trojan.Win32.Hesv.gfev is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan.Win32.Hesv.gfev virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine UDS:Trojan.Win32.Hesv.gfev?


File Info:

name: DFF0F541C73B3E8B3966.mlw
path: /opt/CAPEv2/storage/binaries/d2c60f3601cf7a85fd81115c1a192a64d46b9360d993e8295ad453d60aae1f96
crc32: B0125215
md5: dff0f541c73b3e8b39663963c59b87a9
sha1: 36dec9c18098c787ef6376e1f5832acf96dd7c72
sha256: d2c60f3601cf7a85fd81115c1a192a64d46b9360d993e8295ad453d60aae1f96
sha512: e0dea77d742d7ce29e6aa538873282c410f6a8b25a19164ee8eb88e7e470ba6692aae79c9270c5172b4edf52b8966d62a8bc4c0d9bf01c74e9f70a407dc1254f
ssdeep: 3072:y630thKdTAodJza64TRnltulOuQuT1XwfTVXz5LsNfkJOGsLo3XEqfXao:y0ZETpNzhQmLsLcx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14554F60373EA945ED9B277B05EBAD355CB37BD299233C21F3284191F5EA1A405E22372
sha3_384: bcb34a03a5552df51518005a005775cb361a3b2c9c34d9c2a5a42b3d63ab84e5761bc44ae2a8d5a49e3ae605673325b1
ep_bytes: 60be001047008dbe0000f9ff57eb0b90
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

UDS:Trojan.Win32.Hesv.gfev also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Strictor.267438
ALYacGen:Variant.Strictor.267438
MalwarebytesAutoIt.Trojan.MalPack.DDS
ZillyaTrojan.Hesv.Win32.5585
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.AutoIt.a
CyrenW32/S-79628cd6!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Hesv.gfev
BitDefenderGen:Variant.Strictor.267438
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10be9d88
EmsisoftGen:Variant.Strictor.267438 (B)
F-SecureHeuristic.HEUR/AGEN.1363450
VIPREGen:Variant.Strictor.267438
McAfee-GW-EditionBehavesLike.Win32.RealProtect.dt
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.dff0f541c73b3e8b
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.1K78EN9
JiangminTrojan.Hesv.dnb
AviraHEUR/AGEN.1363450
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.TSGeneric
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Strictor.D414AE
ZoneAlarmUDS:Trojan.Win32.Hesv.gfev
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3HEUR/Fakon.mwf.X1381
McAfeeArtemis!DFF0F541C73B
Cylanceunsafe
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
IkarusTrojan.Autoit
MaxSecureTrojan.Malware.77298014.susgen
FortinetW32/ULPM.16C0!tr
BitDefenderThetaGen:NN.ZexaF.36196.rm0@amLoo5pi
AVGWin32:Malware-gen
Cybereasonmalicious.1c73b3
DeepInstinctMALICIOUS

How to remove UDS:Trojan.Win32.Hesv.gfev?

UDS:Trojan.Win32.Hesv.gfev removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment