Trojan

Trojan.Win32.Hedo.avod removal instruction

Malware Removal

The Trojan.Win32.Hedo.avod is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Hedo.avod virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Hedo.avod?


File Info:

name: 9EC2741D367237DA0C8D.mlw
path: /opt/CAPEv2/storage/binaries/367f92a053b4d6548470550b9ef8edd1d55a86948339e966bf6322f04f808007
crc32: 312148A7
md5: 9ec2741d367237da0c8d488e1bfeff8d
sha1: 49473cd67966238b672793344ea8ec6fbc2d548c
sha256: 367f92a053b4d6548470550b9ef8edd1d55a86948339e966bf6322f04f808007
sha512: 6746bf29bfbe39afa5b020fffaca6c21e714466e2c5333b11d8ffbbc5553d13937be95e790995fce9eef93b306a93859aa22ce880ebb44d4822e462d769dd9a9
ssdeep: 6144:2sVDVaVDV8VDVJVDV8VDVaVDV8VDVLVDV8VDVaVDV8VDV+VJVDV8VDVaVDV8VDVb:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ECE57E43A5CCB576CB9B02372A94DA3811E82190D7484B02FBFD397ABFC6AD1358E355
sha3_384: 522f3c411f4c65bed47a27b695c245e58a6f2b8cab499998cce6c1389dc996a975dcb1b295dcb9944f966b6c6160b6d7
ep_bytes: 60be158040008dbeeb8fffff5783cdff
timestamp: 2016-03-01 22:44:44

Version Info:

0: [No Data]

Trojan.Win32.Hedo.avod also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EYLR
FireEyeGeneric.mg.9ec2741d367237da
McAfeeArtemis!9EC2741D3672
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2649520
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 0058876d1 )
AlibabaTrojan:Win32/Generic.df490916
K7GWTrojan ( 0058876d1 )
Cybereasonmalicious.d36723
VirITTrojan.Win32.Agent3.CIEB
CyrenW32/Agent.DOR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.ADMM
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Hedo.avod
BitDefenderTrojan.Agent.EYLR
NANO-AntivirusTrojan.Win32.Agent.epwdel
AvastWin32:Malware-gen
TencentTrojan.Win32.Agent.wb
EmsisoftTrojan.Agent.EYLR (B)
DrWebTrojan.Siggen15.22576
TrendMicroSuspicious
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.dlnq
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3516521
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.1YNUJ22
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.QE.C4744266
BitDefenderThetaGen:NN.ZexaF.34182.epJfaix7qjpi
ALYacTrojan.Agent.EYLR
MAXmalware (ai score=81)
VBA32Trojan.Agentb
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallSuspicious
RisingTrojan.Agent!1.D9AC (C64:YzY0Olh+g3JhjpAN)
YandexTrojan.Fuery!D+JupAt/MK4
FortinetW32/Agent.ADMM!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (W)
MaxSecureTrojan.Malware.7164915.susgen

How to remove Trojan.Win32.Hedo.avod?

Trojan.Win32.Hedo.avod removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment