Trojan

Trojan.Win32.Eb.blo removal tips

Malware Removal

The Trojan.Win32.Eb.blo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.blo virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Eb.blo?


File Info:

crc32: 1A259597
md5: 3e587c3d4721a569d06296a59ba91181
name: 3E587C3D4721A569D06296A59BA91181.mlw
sha1: 902b01aeda7f2a9c1fb5d70ac8067cd53c27984e
sha256: 9f4bd37b7bea942a0c42c61810160652de4eabe2e80425ffa8fd2fe9b8473b0b
sha512: ed1951b150edb4b729737752e7657d7b5e4c437ac57183a1a830e489b2527fe1464438ffeea32927b2ff34265c78521b0b6619fa4cad58787730f668d7c60a39
ssdeep: 98304:X2Yl90tgoIbYuhkikmybPq8P+2cnOq6nZQbv2yp7GgMa2DBE38W6DevBMpq1hy3:XH0+0u+ZyGoayblJMu3/vCZAbBDPMQ4
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, wodkafull
ProductVersion: 1.0.16
TranslationUsa: 0x0273 0x0080

Trojan.Win32.Eb.blo also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36033117
FireEyeGeneric.mg.3e587c3d4721a569
CAT-QuickHealTrojan.Wacatac
ALYacTrojan.GenericKD.36033117
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00575d741 )
BitDefenderTrojan.GenericKD.36033117
K7GWTrojan ( 00575d741 )
Cybereasonmalicious.eda7f2
BitDefenderThetaGen:NN.ZexaF.34780.@pKfaiZPwnhG
CyrenW32/Glupteba.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Packed.Predatorthief-9820523-0
KasperskyTrojan.Win32.Eb.blo
AlibabaTrojan:Win32/Azorult.551235e3
ViRobotTrojan.Win32.Z.Wacatac.4444160
TencentWin32.Trojan.Ranumbot.Lmbg
Ad-AwareTrojan.GenericKD.36033117
SophosMal/Generic-S
ComodoMalware@#20xic8bkoypwo
F-SecureTrojan.TR/AD.GoCloudnet.wwdjs
ZillyaTrojan.Eb.Win32.307
TrendMicroTROJ_GEN.R002C0DAB21
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
EmsisoftTrojan.GenericKD.36033117 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Eb.ij
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.wwdjs
MAXmalware (ai score=81)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Azorult.MR!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D225D25D
ZoneAlarmTrojan.Win32.Eb.blo
GDataTrojan.GenericKD.36033117
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R362419
Acronissuspicious
McAfeeArtemis!3E587C3D4721
VBA32Trojan.Zenpak
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32WinGo/RanumBot.J
TrendMicro-HouseCallTROJ_GEN.R002C0DAB21
RisingRansom.ScarletFlash!8.1142F (TFE:5:IxrZyQ9FrYU)
YandexTrojan.Eb!PURTKSCoCco
IkarusTrojan.Win32.Ranumbot
FortinetW32/Kryptik.HIRY!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.PWS.d75

How to remove Trojan.Win32.Eb.blo?

Trojan.Win32.Eb.blo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment