Trojan

Trojan.Win32.Hedo.awur removal instruction

Malware Removal

The Trojan.Win32.Hedo.awur is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Hedo.awur virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Hedo.awur?


File Info:

name: E153A8A730A38BDBC94B.mlw
path: /opt/CAPEv2/storage/binaries/8b2c10214b204ae6a79017d712db3dc484ee4e98c3f819e77971e6d1846207c6
crc32: 2B509BC4
md5: e153a8a730a38bdbc94b53775cb61fea
sha1: ca3730600943f575d848ef97bbca612ab4f591ae
sha256: 8b2c10214b204ae6a79017d712db3dc484ee4e98c3f819e77971e6d1846207c6
sha512: e8ee03a0dddc5d720986569039613a684c454bf2e2054158c8b4b74cc143d61ff55754a9d119ea4cc8d871810185253cc481552e2b4a8a54c93a6fd891626227
ssdeep: 6144:2OVDV8VDVaVDV8VDVmVLVDV8VDVaVDV8VDVZVDV8VDVaVDV8VDVLVDV8VDVaVDVm:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1767E43A9CCB576CB9B02372A94DA3811E82190D7484B02FBFD397ABFC6AD1354E355
sha3_384: 90f1927d14ed4eef905ac7e35b852fbc70442694f12f63e26f70f59ff4588f483844b27fcba8f8bd51e776e7b3642518
ep_bytes: 60be158040008dbeeb8fffff5783cdff
timestamp: 2016-03-01 22:44:44

Version Info:

0: [No Data]

Trojan.Win32.Hedo.awur also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Hedo.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.22576
MicroWorld-eScanTrojan.Agent.EYLR
FireEyeGeneric.mg.e153a8a730a38bdb
McAfeeArtemis!E153A8A730A3
CylanceUnsafe
SangforTrojan.Win32.Hedo.awur
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.Agent.EYLR
K7GWTrojan ( 0058876d1 )
K7AntiVirusTrojan ( 0058876d1 )
BitDefenderThetaGen:NN.ZexaF.34182.@pJfaix7qjpi
VirITTrojan.Win32.Agent3.CIEB
CyrenW32/Agent.DOR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.ADMM
TrendMicro-HouseCallSuspicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Hedo.awur
AlibabaTrojan:Win32/Generic.6b80431a
NANO-AntivirusTrojan.Win32.Agent.epwdel
RisingTrojan.Agent!1.D9AC (RDMK:cmRtazpndF0mLEJSUOYSZ3YSC9II)
SophosMal/Generic-S
ZillyaTrojan.Agent.Win32.2614368
TrendMicroSuspicious
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftTrojan.Agent.EYLR (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.dlnq
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3516521
MicrosoftPWS:Win32/Zbot!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.1YNUJ22
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.QE.C4721129
VBA32Trojan.Agentb
ALYacTrojan.Agent.EYLR
MalwarebytesTrojan.Dropper
PandaTrj/Genetic.gen
APEXMalicious
TencentTrojan.Win32.Agent.wb
YandexTrojan.Fuery!D+JupAt/MK4
MAXmalware (ai score=87)
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.ADMM!tr
AVGWin32:Malware-gen
Cybereasonmalicious.730a38
AvastWin32:Malware-gen

How to remove Trojan.Win32.Hedo.awur?

Trojan.Win32.Hedo.awur removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment