Trojan

Should I remove “Trojan.Win32.Eb.bel”?

Malware Removal

The Trojan.Win32.Eb.bel is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.bel virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

How to determine Trojan.Win32.Eb.bel?


File Info:

crc32: 93DFAE08
md5: 22a6f7015673dc07ac90c321b9e19ee9
name: 22A6F7015673DC07AC90C321B9E19EE9.mlw
sha1: 1d4729b25090ed80648d184ce9e63d0fe79142a4
sha256: 8df0f8472aab2ccc6577c04b65a10d4dcdc20f95e63114f651c6340ad8c2a2d7
sha512: 95fb1d852bd7790c66f8ac2453a1240a59cbc321875c24c290f7ab3ba7462bc75a1756fe0bad754ebde53a59b4282d3dcf5a7823384fcb1eb1395318d54aaf1a
ssdeep: 98304:5nBnhpI6nDnevz+dEibKeNMErvUVx0FFTmRTlaj9uOWPrfyT8m6aIcKma9ouTiE:MCDeL/i+EYgP4UjhUbcKmlJZjCgNFRe
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwylbifes.acs
FileVers: 26.26.361
ProductionVersion: 1.0.22.25
Copyright: Copyrighz (C) 2020, pagkafug
TranslationUsa: 0x0772 0x0089

Trojan.Win32.Eb.bel also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AntiSandbox.GenericKD.45001569
FireEyeGeneric.mg.22a6f7015673dc07
Qihoo-360Generic/HEUR/QVM11.1.E9E3.Malware.Gen
McAfeeGenericRXAA-AA!22A6F7015673
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.AntiSandbox.GenericKD.45001569
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.34700.@pKfaetks0mG
CyrenW32/Kryptik.CRY.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Bulz-9808185-0
KasperskyTrojan.Win32.Eb.bel
AlibabaTrojan:Win32/Glupteba.095f492b
Ad-AwareTrojan.AntiSandbox.GenericKD.45001569
SophosMal/Generic-S
F-SecureTrojan.TR/AD.GoCloudnet.doytm
DrWebTrojan.DownLoader36.28337
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
EmsisoftTrojan.AntiSandbox.GenericKD.45001569 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.AntiSandbox.GenericKD.45001569
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.doytm
MAXmalware (ai score=81)
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.AntiSandbox.Generic.D2AEAB61
ZoneAlarmTrojan.Win32.Eb.bel
MicrosoftTrojan:Win32/Glupteba.NK!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R357709
Acronissuspicious
VBA32BScope.Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32a variant of Win32/Kryptik.HIFB
RisingTrojan.Kryptik!8.8 (TFE:5:G6GudicZAaE)
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_89%
FortinetW32/Kryptik.HIFA!tr
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan.Win32.Eb.bel?

Trojan.Win32.Eb.bel removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment