Trojan

Trojan.Win32.Eb.blm removal instruction

Malware Removal

The Trojan.Win32.Eb.blm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.blm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Eb.blm?


File Info:

crc32: 874DFDEC
md5: c95626fd1c7453b21e94b5faf46d6c35
name: C95626FD1C7453B21E94B5FAF46D6C35.mlw
sha1: 35a38dd9b88f1f2f5ba4f623093934b1cd9d0bf8
sha256: 3afaa2ff3be6dada6a74793cf9ce5f7229d00508071c656e7ce3dce1fb42e94c
sha512: be6b2ec25bff59102f52c04edb742f7397afb12bfc836bd9f3de82db15c3d54075d0d69d390414682d7149441c0bb83d6b321656747e14d66630ac0515185bc8
ssdeep: 98304:kzbCUZFlPokhruVFBm7QGoZwkzYvloCqJP8/fxwA4h7Cae45M4Zu5iAuGlA3eDS:YAkyRZoNxn4hB6P56OeYGYYTudT1QkY
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, wodkafull
ProductVersion: 1.0.16
TranslationUsa: 0x0273 0x0080

Trojan.Win32.Eb.blm also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AntiSandbox.GenericKD.36032541
FireEyeGeneric.mg.c95626fd1c7453b2
CAT-QuickHealTrojan.Wacatac
ALYacTrojan.AntiSandbox.GenericKD.36032541
MalwarebytesTrojan.MalPack.GS
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.AntiSandbox.GenericKD.36032541
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9b88f1
CyrenW32/Glupteba.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyTrojan.Win32.Eb.blm
AlibabaTrojan:Win32/Azorult.d82f4449
ViRobotTrojan.Win32.Z.Antisandbox.4443648.A
AegisLabTrojan.Win32.Malicious.4!c
TencentWin32.Trojan.Eb.Syrm
Ad-AwareTrojan.AntiSandbox.GenericKD.36032541
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1140248
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R049C0DAB21
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
EmsisoftTrojan.AntiSandbox.GenericKD.36032541 (B)
IkarusTrojan.WinGo.Ranumbot
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1140248
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Azorult.MR!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.AntiSandbox.Generic.D225D01D
ZoneAlarmTrojan.Win32.Eb.blm
GDataTrojan.AntiSandbox.GenericKD.36032541
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4297209
Acronissuspicious
McAfeeArtemis!C95626FD1C74
VBA32BScope.Trojan.Wacatac
PandaTrj/RnkBend.A
ESET-NOD32WinGo/RanumBot.J
TrendMicro-HouseCallTROJ_GEN.R049C0DAB21
RisingTrojan.Kryptik!8.8 (TFE:5:0txcNo6oK6D)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIRY!tr
BitDefenderThetaGen:NN.ZexaF.34760.@pKfa08l3feG
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Win32/Trojan.4b2

How to remove Trojan.Win32.Eb.blm?

Trojan.Win32.Eb.blm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment