Trojan

Trojan.Win32.Hedo.avei (file analysis)

Malware Removal

The Trojan.Win32.Hedo.avei is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Hedo.avei virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Hedo.avei?


File Info:

name: E515AED4F3DFED87A390.mlw
path: /opt/CAPEv2/storage/binaries/19f627fc18bcaf906aca6e1054b7886b6339aabf26d2f2d4d0841bae64d7a4fa
crc32: 143025BF
md5: e515aed4f3dfed87a390abe9ad454362
sha1: e588677ba5dc21052fef525210e417c3d34b849a
sha256: 19f627fc18bcaf906aca6e1054b7886b6339aabf26d2f2d4d0841bae64d7a4fa
sha512: 2eeccebe5a0422fc6f271488dd03b6803f3ddd1551e84fd708074cf0a749bf5bae36573e89746020819716e6a535c2a9f99962d2bfed4378a1cfda997c307f5f
ssdeep: 6144:2WV1VtVtVtVVVtVtVtV2VtVtV1VtVtVtVVVtVtVtVvVtVtV1VtVtVtVVVtVtVtVn:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T101E57E43A5CCB576CB9B02372A94DA3811E82190D7484B02FBFD397ABFC6AD1358E355
sha3_384: 33b013e37708dcdcd0227acdfea33bfe4bcab3c694ae54829ad2b9097f01190d3820ca984eb8c3b97c1a729716baab1d
ep_bytes: 60be158040008dbeeb8fffff5783cdff
timestamp: 2016-03-01 22:44:44

Version Info:

0: [No Data]

Trojan.Win32.Hedo.avei also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EYLR
FireEyeGeneric.mg.e515aed4f3dfed87
ALYacTrojan.Agent.EYLR
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2618515
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 0058876d1 )
AlibabaTrojan:Win32/Generic.02a3bf6e
K7GWTrojan ( 0058876d1 )
Cybereasonmalicious.4f3dfe
BitDefenderThetaGen:NN.ZexaF.34182.6oJfaix7qjpi
VirITTrojan.Win32.Agent3.CIEB
CyrenW32/Agent.DOR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.ADMM
TrendMicro-HouseCallSuspicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Hedo.avei
BitDefenderTrojan.Agent.EYLR
NANO-AntivirusTrojan.Win32.Agent.epwdel
AvastWin32:Malware-gen
TencentTrojan.Win32.Agent.wb
EmsisoftTrojan.Agent.EYLR (B)
DrWebTrojan.Siggen15.22576
TrendMicroSuspicious
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-S
APEXMalicious
JiangminTrojan.Agent.dlnq
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3516521
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.Z.Agent.3055616.BK
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.1YNUJ22
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.QE.C4721129
McAfeeArtemis!E515AED4F3DF
MAXmalware (ai score=82)
VBA32Trojan.Agentb
MalwarebytesTrojan.Dropper
RisingTrojan.Agent!1.D9AC (C64:YzY0Olh+g3JSGpKB)
YandexTrojan.Agent!dIEBCPfqIxw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.ADMM!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Hedo.avei?

Trojan.Win32.Hedo.avei removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment