Trojan

How to remove “Trojan.Win32.Eb.bjp”?

Malware Removal

The Trojan.Win32.Eb.bjp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.bjp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Tswana
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Eb.bjp?


File Info:

crc32: BB48E5BF
md5: 92863ab5395e09c1d2144a1e01156dac
name: 92863AB5395E09C1D2144A1E01156DAC.mlw
sha1: 0132b0680c4fe203fc1721a3aa68a9cd79663b12
sha256: 053ae6e2a6962050113837191729a27451835200495a0d7fa410e3a94f2beee8
sha512: 7d6ca69cde3dbd7f6c87e03026382d3b6afc26f9843f385ffb98e48e964b401b42b27bd1d9e4248ffeafe8d1c2afae9c03aa91a4cf8a83a724b65c14c619f7c2
ssdeep: 98304:aKBycIlF3VejBN6vQlAi/+tp6E53ZxZ8cZ0PAQ7psQMRif2Cjstx87pWe6jRsty:a5on6vOCmcZD3RbnxhaZe19dU6D2lZD
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Trojan.Win32.Eb.bjp also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.57370
MicroWorld-eScanTrojan.GenericKD.35992795
FireEyeGeneric.mg.92863ab5395e09c1
CAT-QuickHealTrojan.Wacatac
McAfeeGenericRXAA-AA!92863AB5395E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.ArchSMS.lsIq
SangforMalware
K7AntiVirusTrojan ( 00575aaa1 )
BitDefenderTrojan.GenericKD.35992795
K7GWTrojan ( 00575aaa1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34760.@pKfa4zzLxdG
CyrenW32/Trojan.WYWI-2358
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Glupteba-9819304-0
KasperskyTrojan.Win32.Eb.bjp
AlibabaTrojan:Win32/Glupteba.de2a19ad
ViRobotTrojan.Win32.C.Agent.4467200
RisingTrojan.Kryptik!8.8 (TFE:5:nt4Q08fYDcI)
Ad-AwareTrojan.GenericKD.35992795
EmsisoftTrojan.GenericKD.35992795 (B)
ZillyaTrojan.Zenpak.Win32.5302
TrendMicroTROJ_GEN.R002C0DA721
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/AD.GoCloudnet.uqvhi
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Glupteba.NW!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D22534DB
ZoneAlarmTrojan.Win32.Eb.bjp
GDataTrojan.GenericKD.35992795
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R361893
Acronissuspicious
VBA32BScope.Trojan.Caynamer
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.GS
PandaTrj/Agent.ALS
ESET-NOD32a variant of Win32/Kryptik.HIPB
TrendMicro-HouseCallTROJ_GEN.R002C0DA721
TencentWin32.Trojan.Eb.Hsig
YandexTrojan.Igent.bU6UXj.9
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_76%
FortinetW32/Kryptik.HIFA!tr
WebrootW32.Trojan.Gen
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.5395e0
AvastWin32:PWSX-gen [Trj]
Qihoo-360Generic/HEUR/QVM11.1.5E9B.Malware.Gen

How to remove Trojan.Win32.Eb.bjp?

Trojan.Win32.Eb.bjp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment