Trojan

About “Trojan.Win32.Hedo.aruc” infection

Malware Removal

The Trojan.Win32.Hedo.aruc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Hedo.aruc virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Hedo.aruc?


File Info:

name: 28B0224D1138A6B0987B.mlw
path: /opt/CAPEv2/storage/binaries/020910f37c3d374649d7fa9652983b1f763a552f568cd97a56b8e83a7c10a201
crc32: A195F889
md5: 28b0224d1138a6b0987b301869fb3dc8
sha1: 2e88cf98286d3226ee831cf86be692478613e4b6
sha256: 020910f37c3d374649d7fa9652983b1f763a552f568cd97a56b8e83a7c10a201
sha512: b4d3eb641a3eea0d7d90af5ea6ef3b7c97a5ef44b756c04235ed726e0fdfc7c80e68b56afb26e633ac95d14ff55379353d08abbb948feeb089a0a3d2ebce30b8
ssdeep: 6144:2tVGVvVgVvVGVvV7VvVGVvVwVvVGVvV7VvVGVvVgVvVGVvV7VvVGVvVKVGVvV7Vz:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BF667E43A9CCB576CB9B02372A94DA3811E82190D7484B02FBFD397ABFC6AD1354E355
sha3_384: 62b59342341792e0306cceab15b53ae0518fcd5daec64aeeca7b434e64581b047666853194e4b7743f414928430c6d2d
ep_bytes: 60be158040008dbeeb8fffff5783cdff
timestamp: 2016-03-01 22:44:44

Version Info:

0: [No Data]

Trojan.Win32.Hedo.aruc also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EYLR
FireEyeGeneric.mg.28b0224d1138a6b0
McAfeeArtemis!28B0224D1138
CylanceUnsafe
SangforTrojan.Win32.Hedo.aruc
K7AntiVirusTrojan ( 0058876d1 )
BitDefenderTrojan.Agent.EYLR
K7GWTrojan ( 0058876d1 )
Cybereasonmalicious.d1138a
BitDefenderThetaGen:NN.ZexaF.34182.@pJfaix7qjpi
VirITTrojan.Win32.Agent3.CIEB
CyrenW32/Agent.DOR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.ADMM
TrendMicro-HouseCallSuspicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Hedo.aruc
AlibabaTrojan:Win32/Generic.61b6832a
NANO-AntivirusTrojan.Win32.Agent.epwdel
ViRobotTrojan.Win32.Z.Agent.6922240.R
RisingTrojan.Agent!1.D9AC (CLOUD)
SophosMal/Generic-S
DrWebTrojan.Siggen15.22576
ZillyaTrojan.Agent.Win32.2616863
TrendMicroSuspicious
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.Agent.EYLR (B)
APEXMalicious
JiangminTrojan.Agent.dlnq
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3516521
GridinsoftRansom.Win32.Zbot.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmTrojan.Win32.Hedo.aruc
GDataWin32.Trojan.PSE.1YNUJ22
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.QE.C4721129
VBA32Trojan.Agentb
MalwarebytesTrojan.Dropper
PandaTrj/Genetic.gen
TencentTrojan.Win32.Agent.wb
YandexTrojan.Fuery!D+JupAt/MK4
MAXmalware (ai score=83)
FortinetW32/Agent.ADMM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Hedo.aruc?

Trojan.Win32.Hedo.aruc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment