Trojan

Trojan.Win32.Biodata.eo removal guide

Malware Removal

The Trojan.Win32.Biodata.eo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Biodata.eo virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Biodata.eo?


File Info:

name: 94394247C21A559C0E73.mlw
path: /opt/CAPEv2/storage/binaries/a69f3c5bd2e22aa8d830252386a689b28bbe5834fcfe675293707531e5fc4a07
crc32: 46C73E77
md5: 94394247c21a559c0e7324e79e02d242
sha1: 79bef3fafbb962a341869ba1da4866cb5731cbce
sha256: a69f3c5bd2e22aa8d830252386a689b28bbe5834fcfe675293707531e5fc4a07
sha512: 245e0c3add620c655b5019a4eb25cd5ad7b829eab6b123407c2960c6e50b3f8add1097608636c566ffe78a1fc921b74cf15fc812fcbe90c526a19a4182c36bbb
ssdeep: 49152:K2ZqB5J85BQJ8R4SeXqhYN8uQxEHBhDCNqQadyQ3F:U5J8vvR4SHhl6BhMqHyQ3F
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13EB52381EAD098B3D6F619370039B759593CBD209D30EE7F5B902D39A9750C2B721EA3
sha3_384: 7a4d7d89d13bd5d7d3e536a705eba4f3668adda62680b99151786020f2a44c2d39d3b179c09ed67299729b365f8e3f17
ep_bytes: e88a040000e98efeffff3b0db8a14300
timestamp: 2017-07-25 08:59:43

Version Info:

0: [No Data]

Trojan.Win32.Biodata.eo also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Biodata.4!c
MicroWorld-eScanTrojan.GenericKD.12741835
ClamAVWin.Dropper.RevengeRAT-7059301-0
FireEyeGeneric.mg.94394247c21a559c
McAfeeArtemis!94394247C21A
MalwarebytesMalware.Heuristic.1003
SangforTrojan.Win32.Biodata.eo
K7AntiVirusTrojan-Downloader ( 00516d9e1 )
K7GWTrojan-Downloader ( 00516d9e1 )
Cybereasonmalicious.7c21a5
CyrenW32/Trojan.DQD.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Biodata.eo
BitDefenderTrojan.GenericKD.12741835
NANO-AntivirusTrojan.Win32.Delf.ewzspk
AvastWin32:Malware-gen
TencentWin32.Trojan.Biodata.Hrev
Ad-AwareTrojan.GenericKD.12741835
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Amtar.JAOJ@5iyj1f
DrWebTrojan.DownLoader26.23662
VIPRETrojan.GenericKD.12741835
TrendMicroTROJ_DELF.XXXK
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.12741835 (B)
IkarusTrojan-Downloader.Win32.Delf
GDataWin32.Application.OpenCandy.R
AviraHEUR/AGEN.1214482
Antiy-AVLTrojan/Generic.ASMalwS.4A8C
KingsoftWin32.Troj.Biodata.eo.(kcloud)
ArcabitTrojan.Generic.DC26CCB
MicrosoftTrojan:Win32/Occamy.CA6
GoogleDetected
ALYacTrojan.GenericKD.12741835
MAXmalware (ai score=94)
VBA32Backdoor.MSIL.Agent
CylanceUnsafe
TrendMicro-HouseCallTROJ_DELF.XXXK
RisingDownloader.Delf!8.16F (TFE:5:cynYvj0DetE)
YandexTrojan.GenAsa!vF/5FxNflMo
SentinelOneStatic AI – Malicious SFX
MaxSecureTrojan.Malware.73768868.susgen
FortinetRiskware/uTorrent.E6A1
BitDefenderThetaAI:Packer.D35B856721
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Biodata.eo?

Trojan.Win32.Biodata.eo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment