Trojan

Trojan.Win32.Hedo.bwv removal instruction

Malware Removal

The Trojan.Win32.Hedo.bwv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Hedo.bwv virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Hedo.bwv?


File Info:

name: 8BAD1B5436A826F8BCE2.mlw
path: /opt/CAPEv2/storage/binaries/d45dac678cb8fba7f894e228a3c5c70c2c6c0478d03cb11677b790f29b40dced
crc32: 6BD1AB37
md5: 8bad1b5436a826f8bce2d4b3266fad14
sha1: 017ba2528f674f5e6ee42959eaf73a978dbb143a
sha256: d45dac678cb8fba7f894e228a3c5c70c2c6c0478d03cb11677b790f29b40dced
sha512: c7c46dad79088c89bdd93034780eaf5e45202656c8567172c9fe6e16eb97acd4dce01d41ac3b16724715b1151f1687c1809f52de50fe41e2b315ed1c0a32b292
ssdeep: 6144:2ZVDViVDVyVDViVDVZVDViVDVZVDViVDVZVDViVDVdVDViVDVZVDViVDVZVDViVb:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EDF58E43A5CCB576CB9B02372A94DA3811E82190D7484B02FBFD397ABFC6AD1358E355
sha3_384: 4b3f96ce33bed2b1be51e160a593ef9532b7a0c0526791d76156b73186b9db8c13f955f24e5a81d526899370987eada7
ep_bytes: 60be158040008dbeeb8fffff5783cdff
timestamp: 2016-03-01 22:44:44

Version Info:

0: [No Data]

Trojan.Win32.Hedo.bwv also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Hedo.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EYLR
FireEyeGeneric.mg.8bad1b5436a826f8
CAT-QuickHealTrojan.IGENERIC
McAfeeArtemis!8BAD1B5436A8
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2590462
SangforTrojan.Win32.Hedo.bwv
K7AntiVirusTrojan ( 0058876d1 )
AlibabaTrojan:Win32/Generic.f4d629f7
K7GWTrojan ( 0058876d1 )
Cybereasonmalicious.436a82
VirITTrojan.Win32.Agent3.CIEB
CyrenW32/Agent.DOR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.ADMM
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Hedo.bwv
BitDefenderTrojan.Agent.EYLR
NANO-AntivirusTrojan.Win32.Agent.epwdel
TencentTrojan.Win32.Agent.wb
Ad-AwareTrojan.Agent.EYLR
EmsisoftTrojan.Agent.EYLR (B)
DrWebTrojan.Siggen15.22576
TrendMicroSuspicious
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosMal/Generic-S
GDataWin32.Trojan.PSE.1YNUJ22
JiangminTrojan.Agent.dlnq
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34AABA2
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Ymacco.ABD4
AhnLab-V3Trojan/Win.QE.C4744266
BitDefenderThetaGen:NN.ZexaF.34114.spJfaix7qjpi
ALYacTrojan.Agent.EYLR
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.1244890415
TrendMicro-HouseCallSuspicious
RisingTrojan.Agent!1.D9AC (CLOUD)
YandexTrojan.Agent!eDYrdfbf3Wo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.ADMM!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Hedo.bwv?

Trojan.Win32.Hedo.bwv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment