Malware

Win32/Bicololo.HW removal instruction

Malware Removal

The Win32/Bicololo.HW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Bicololo.HW virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • The sample wrote data to the system hosts file.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

pqy-84.turismo-mendoza.com

How to determine Win32/Bicololo.HW?


File Info:

crc32: 4EEC18D5
md5: f89db7b4bbbed351705f45289fdbc9b9
name: F89DB7B4BBBED351705F45289FDBC9B9.mlw
sha1: 4f3d71954ea6096eaa583a52ddbc4a682a5bcfc3
sha256: 1a5927cf2363a3531a539f20fa48b40a0428b3959934527fc117b7a229215e7b
sha512: 13c081ffc724f1c3f197929cb7b81306ecce775e17b5bc86047aab7df2a4db1fd323ba6b4b498db4890fccc34afee3ba46ccf8cc7764cf3217dd7de9c7ec8dcf
ssdeep: 12288:eCp0jH/Op7CPsiuEyCadYiwDhU5Qs1nC31hMXkpaHCVRK5v8sBip0tvZ:eCp0jfOoPsiuPCYwDhxIn2EXkgHCIiKX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2012 Oleg N. Scherbakov
InternalName: 7ZSfxMod
FileVersion: 1.6.0.2712
CompanyName: Oleg N. Scherbakov
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.6.0.2712
FileDescription: 7z Setup SFX (x86)
OriginalFilename: 7ZSfxMod_x86.exe
Translation: 0x0000 0x04b0

Win32/Bicololo.HW also known as:

ClamAVWin.Trojan.Mcazm-6895619-0
SangforTrojan.Win32.Bicololo.HW
K7GWTrojan ( 004e8b381 )
K7AntiVirusTrojan ( 004e8b381 )
SymantecTrojan.Gen.2
ESET-NOD32Win32/Bicololo.HW
APEXMalicious
AvastWin32:GenMalicious-ACJ [Trj]
Kasperskynot-a-virus:Downloader.Win32.LMN.vymu
NANO-AntivirusTrojan.Win32.Bicololo.dfrqwv
TencentWin32.Trojan.Strictor.Eerd
SophosMal/Bicololo-A
ComodoMalware@#1841f62pwt848
BitDefenderThetaGen:NN.ZexaF.34236.Kq3@aGeMzLak
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.35JF14
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
WebrootW32.Malware.Gen
KingsoftWin32.Troj.Badur.jh.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!F89DB7B4BBBE
PandaTrj/Chgt.F
TrendMicro-HouseCallTROJ_SPNR.35JF14
IkarusTrojan.Win32.Badur
FortinetW32/Badur.HW!tr
AVGWin32:GenMalicious-ACJ [Trj]
Paloaltogeneric.ml

How to remove Win32/Bicololo.HW?

Win32/Bicololo.HW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment