Trojan

Trojan.Win32.Eb.blq (file analysis)

Malware Removal

The Trojan.Win32.Eb.blq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.blq virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Eb.blq?


File Info:

crc32: 1C5E95F1
md5: c6da3312a93405f9aeb408149128612b
name: C6DA3312A93405F9AEB408149128612B.mlw
sha1: 5cbff7adf51d17afa908ccc14453fd2cb870e290
sha256: 1d931916af59294dfccd1dd6929cd992deb87c222e2049ce66effb203e8ff77f
sha512: 32e13ebc8a8206c843b43675fbfdf41da26adcf606bc4535441a9c27133f666b76748f3e247146f6fe811a52f6485fa4ddd41f88dede8077fa07e4a99916192c
ssdeep: 98304:k31u9oZqX/rS0+EjHpTfsjqhhbYHkEGUGd2asyCovJ3Cr1N7UxG9gSb64tsDu3B:k3svX/rS05QjuhcGUhyHF+qK3K5+L0q
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, wodkafull
ProductVersion: 1.0.17
TranslationUsa: 0x0273 0x0080

Trojan.Win32.Eb.blq also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45405554
FireEyeGeneric.mg.c6da3312a93405f9
CAT-QuickHealTrojan.IGENERIC
McAfeeArtemis!C6DA3312A934
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45405554
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_80% (D)
CyrenW32/Glupteba.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.Eb.blq
AlibabaTrojan:Win32/Azorult.dedd92b8
AegisLabHacktool.Win32.ArchSMS.lsxE
RisingRansom.ScarletFlash!8.1142F (TFE:5:IxrZyQ9FrYU)
Ad-AwareTrojan.GenericKD.45405554
EmsisoftTrojan.GenericKD.45405554 (B)
F-SecureHeuristic.HEUR/AGEN.1122056
ZillyaTrojan.Eb.Win32.283
TrendMicroTROJ_GEN.R002C0DAB21
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosMal/Generic-S
IkarusWin32.SuspectCrc
JiangminTrojan.Eb.ik
AviraHEUR/AGEN.1122056
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Azorult.MR!MTB
GridinsoftTrojan.Win32.Packed.vb
ArcabitTrojan.Generic.D2B4D572
ZoneAlarmTrojan.Win32.Eb.blq
GDataTrojan.GenericKD.45405554
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R362419
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34760.@pKfaClNTnaG
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32WinGo/RanumBot.J
TrendMicro-HouseCallTROJ_GEN.R002C0DAB21
TencentWin32.Trojan.Eb.Taow
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HIRY!tr
WebrootW32.Trojan.Gen
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.334

How to remove Trojan.Win32.Eb.blq?

Trojan.Win32.Eb.blq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment