Trojan

Trojan.Win32.Eb.bkc removal guide

Malware Removal

The Trojan.Win32.Eb.bkc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.bkc virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Tswana
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Eb.bkc?


File Info:

crc32: 23CE2E1D
md5: 6c06d479d43a149b17a4559b8c3dc665
name: 6C06D479D43A149B17A4559B8C3DC665.mlw
sha1: 5ef90a9ac263bb7475c6b3e0fdde0835148f1d72
sha256: beff565ae817fdfa82b67007c63d4cd4fe5f5825774daf1c2285352e7440bb38
sha512: 8f9e4c1227ed798940af10826229f51b2254eda05e6f5800ed117c257a7fe78901f75d44dc6cdd4b8af9761fea9da57ebe60e766d98e38444c9144c2d8ced368
ssdeep: 98304:MISQ9wRMoXitddGzuxdEItogr/RVBgi1DXZrqYGAMELC0oNCrJW0xXQcWh8GJxp:tEoDtnNk4oolQL1cfxD6MGSIPXfjO1v
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Trojan.Win32.Eb.bkc also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36000861
FireEyeGeneric.mg.6c06d479d43a149b
ALYacTrojan.GenericKD.36000861
MalwarebytesTrojan.MalPack.GS
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36000861
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9d43a1
BitDefenderThetaGen:NN.ZexaF.34742.@pKfaieAF!cG
CyrenW32/Trojan.ZCTM-2327
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.Eb.bkc
AlibabaTrojan:Win32/Glupteba.87501469
ViRobotTrojan.Win32.Z.Agent.4468224
TencentWin32.Trojan.Eb.Wogc
Ad-AwareTrojan.GenericKD.36000861
SophosMal/Generic-S
ComodoMalware@#vdr69x8wfc41
F-SecureTrojan.TR/AD.GoCloudnet.cznje
TrendMicroTrojanSpy.Win32.GENKRYPTIK.USMANA621
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
EmsisoftTrojan.GenericKD.36000861 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.cznje
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Glupteba.KMG!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D225545D
ZoneAlarmTrojan.Win32.Eb.bkc
GDataTrojan.GenericKD.36000861
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R361893
Acronissuspicious
McAfeeArtemis!6C06D479D43A
VBA32BScope.Trojan.Caynamer
CylanceUnsafe
PandaTrj/RnkBend.A
ESET-NOD32a variant of Win32/Kryptik.HIPB
TrendMicro-HouseCallTrojanSpy.Win32.GENKRYPTIK.USMANA621
RisingTrojan.Kryptik!8.8 (TFE:5:M4loB2xS0kQ)
IkarusTrojan.SuspectCRC
FortinetW32/Kryptik.HIFA!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.d58

How to remove Trojan.Win32.Eb.bkc?

Trojan.Win32.Eb.bkc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment