Trojan

Trojan.Win32.Hedo.acp (file analysis)

Malware Removal

The Trojan.Win32.Hedo.acp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Hedo.acp virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Hedo.acp?


File Info:

name: D92F8C14F8D18370276C.mlw
path: /opt/CAPEv2/storage/binaries/2364c00b2b1a68238a4b4c80640f62c96d6ea88fac7f251c48c9ccfce2014afe
crc32: 28476679
md5: d92f8c14f8d18370276c9c6376833c9a
sha1: fef6d877ed85de0291ae1238e490a33150057609
sha256: 2364c00b2b1a68238a4b4c80640f62c96d6ea88fac7f251c48c9ccfce2014afe
sha512: 95484a94e56677d1d40e946059eaa484e38719f0fdea0173535904b677e6b3c618e415747385d1a0365dc2604be6898259fe9fe677e6b76c87b4ead6351071f3
ssdeep: 6144:2SV2VSVlVSVNVSVlVSV2VSVlVSVfVSVlVSV2VSVlVSVNVSVlVSV2VSVlVSVtVSVp:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B9C57E43A9CCB576CB9B02372A94DA3811E82190D7484B02FBFD397ABFC6AD1354E355
sha3_384: dae5d3d82df622c22cf2ef7a618680c985803ade422f6e4b14352e07db5e227529c7b324bfff12f68976d8fdec7e44e1
ep_bytes: 60be158040008dbeeb8fffff5783cdff
timestamp: 2016-03-01 22:44:44

Version Info:

0: [No Data]

Trojan.Win32.Hedo.acp also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EYLR
FireEyeGeneric.mg.d92f8c14f8d18370
McAfeeArtemis!D92F8C14F8D1
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2591324
K7AntiVirusTrojan ( 0058876d1 )
K7GWTrojan ( 0058876d1 )
Cybereasonmalicious.4f8d18
BitDefenderThetaGen:NN.ZexaF.34114.IoJfaix7qjpi
VirITTrojan.Win32.Agent3.CIEB
CyrenW32/Agent.DOR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.ADMM
TrendMicro-HouseCallSuspicious
KasperskyTrojan.Win32.Hedo.acp
BitDefenderTrojan.Agent.EYLR
NANO-AntivirusTrojan.Win32.Agent.epwdel
AvastWin32:Malware-gen
TencentTrojan.Win32.Agent.wb
Ad-AwareTrojan.Agent.EYLR
EmsisoftTrojan.Agent.EYLR (B)
DrWebTrojan.Siggen15.22576
TrendMicroSuspicious
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
GDataWin32.Trojan.PSE.1YNUJ22
JiangminTrojan.Agent.dlnq
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.Agent
ArcabitTrojan.Agent.EYLR
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.QE.C4721129
VBA32BScope.Trojan.Wacatac
ALYacTrojan.Agent.EYLR
MAXmalware (ai score=81)
MalwarebytesMalware.AI.1244890415
RisingTrojan.Agent!1.D9AC (RDMK:cmRtazrdeCWSL7z1mCFchqZYkLw5)
YandexTrojan.Agent!rYxZY1q761o
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.ADMM!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Trojan.Win32.Hedo.acp?

Trojan.Win32.Hedo.acp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment