Malware

Spammer:Win32/Hedsen removal tips

Malware Removal

The Spammer:Win32/Hedsen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spammer:Win32/Hedsen virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Romanian
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Spammer:Win32/Hedsen?


File Info:

crc32: A646B252
md5: 3027926beb3d3c977a789755e67169c6
name: 3027926BEB3D3C977A789755E67169C6.mlw
sha1: 74ed5decc33d426a7eb4205f27ec6dd488e5ea96
sha256: 19935046c6107bda1e57937a09823a9b689b7da53d7d9618c1b96a7cd02dae46
sha512: 445d538ca508a81830802552ae74ea5feff1afd674c92cb33bf4bf683177fcfcbba493769467b91a7b23e40850457a379b96c6b288ec47d6da877ba5572809bc
ssdeep: 1536:ifL0SRIfo57Jp+y7lnmaaHVQxN53iQhOLEB25N9Lsi1XOQhUmkXtL8d:k1Is7Jpj7lN4QxNdpOoBELsi12mkdLg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Spammer:Win32/Hedsen also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004b22a51 )
LionicTrojan.Win32.Generic.lZ5Q
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Dyreza.4
CylanceUnsafe
ZillyaTool.Agent.Win32.10543
SangforTrojan.Win32.ZPACK.Gen4
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Hedsen.253e9797
K7GWTrojan ( 004b22a51 )
Cybereasonmalicious.beb3d3
BaiduWin32.Trojan-Downloader.Waski.a
SymantecTrojan Horse
ESET-NOD32Win32/SpamTool.Agent.NFV
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Dyreza.4
NANO-AntivirusTrojan.Win32.MlwGen.dlaxgx
MicroWorld-eScanGen:Variant.Dyreza.4
TencentWin32.Trojan.Crypt.Lfpv
Ad-AwareGen:Variant.Dyreza.4
SophosMal/Generic-R + Troj/Agent-AKVX
ComodoMalware@#2vmajhgajd3t3
BitDefenderThetaGen:NN.ZexaF.34294.iqW@aaXTqshO
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPABOT.WHT
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
FireEyeGeneric.mg.3027926beb3d3c97
EmsisoftGen:Variant.Dyreza.4 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Bot.Gen
AviraTR/Crypt.ZPACK.Gen4
eGambitUnsafe.AI_Score_68%
MicrosoftSpammer:Win32/Hedsen
GDataGen:Variant.Dyreza.4
AhnLab-V3Trojan/Win32.Xema.R133153
McAfeeArtemis!3027926BEB3D
MAXmalware (ai score=100)
VBA32BScope.Trojan.Dyre
MalwarebytesMalware.AI.4115318585
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SPABOT.WHT
RisingTrojan.Generic@ML.99 (RDMK:EQgtB7HKCutx1/sItBDC2w)
YandexSpamTool.Agent!E8OeH6asnnA
IkarusTrojan.Win32.SpamTool
FortinetW32/Kryptik.CTJO!tr
AVGWin32:Malware-gen

How to remove Spammer:Win32/Hedsen?

Spammer:Win32/Hedsen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment