Trojan

Trojan.Win32.Hedo.atii removal

Malware Removal

The Trojan.Win32.Hedo.atii is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Hedo.atii virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Hedo.atii?


File Info:

name: 717944FB54DF73FD2E3A.mlw
path: /opt/CAPEv2/storage/binaries/f933f1015601d752d532cf8611471adabdd73b6c6dc999bf275f814e0c50b442
crc32: 16570C25
md5: 717944fb54df73fd2e3a714261c2ed33
sha1: 22fbb928700c4a3e0efe1a1ce503eff833559475
sha256: f933f1015601d752d532cf8611471adabdd73b6c6dc999bf275f814e0c50b442
sha512: 9f11f41a98302b417376156691068f474d5c5f6b9536df91fc637e12b7f38abd38387ff949d90b6b785cd48ea338a75d5f0ed78e377560a14cc77c02c1fd2d74
ssdeep: 6144:2RVwVvVGVvV7VvVGVvVgVvVGVvV7VvVGVvVVzVvVGVvV7VvVGVvVgVvVGVvV7Vv/:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160D57E43A9CCB576CB9B02372A94DA3811E82190D7484B02FBFD397ABFC6AD1354E355
sha3_384: c605ea8084385d6ac81eaab6c0a69ade990214aa1f6fe9388078cc1e1ba7bd3f92ebaba0db099d5b1e3b699b1b9c60d8
ep_bytes: 60be158040008dbeeb8fffff5783cdff
timestamp: 2016-03-01 22:44:44

Version Info:

0: [No Data]

Trojan.Win32.Hedo.atii also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EYLR
FireEyeGeneric.mg.717944fb54df73fd
CAT-QuickHealTrojan.AgentbPMF.S26395285
McAfeeArtemis!717944FB54DF
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2597244
SangforTrojan.Win32.Hedo.atii
K7AntiVirusTrojan ( 0058876d1 )
AlibabaTrojan:Win32/Generic.923fa0df
K7GWTrojan ( 0058876d1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Agent3.CIEB
CyrenW32/Agent.DOR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.ADMM
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Hedo.atii
BitDefenderTrojan.Agent.EYLR
NANO-AntivirusTrojan.Win32.Agent.epwdel
AvastWin32:Malware-gen
TencentTrojan.Win32.Agent.wb
Ad-AwareTrojan.Agent.EYLR
EmsisoftTrojan.Agent.EYLR (B)
DrWebTrojan.Siggen15.22576
TrendMicroSuspicious
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-S
GDataWin32.Trojan.PSE.1YNUJ22
JiangminTrojan.Agent.dlnq
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3516521
ZoneAlarmTrojan.Win32.Hedo.atii
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.QE.C4721129
BitDefenderThetaGen:NN.ZexaF.34212.3oJfaix7qjpi
ALYacTrojan.Agent.EYLR
MAXmalware (ai score=84)
VBA32Trojan.Agentb
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallSuspicious
RisingTrojan.Agent!1.D9AC (CLOUD)
YandexTrojan.Fuery!D+JupAt/MK4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.ADMM!tr
AVGWin32:Malware-gen
Cybereasonmalicious.b54df7
PandaTrj/Genetic.gen

How to remove Trojan.Win32.Hedo.atii?

Trojan.Win32.Hedo.atii removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment