Trojan

What is “Trojan.Win32.Eb.bmi”?

Malware Removal

The Trojan.Win32.Eb.bmi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.bmi virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Eb.bmi?


File Info:

crc32: 039440A4
md5: 50dbaf0d17a0375c28ce290d785b4694
name: 50DBAF0D17A0375C28CE290D785B4694.mlw
sha1: 9b33e5fba055b6f03c886e071c8c526ecb9a5fe7
sha256: b6871670c5af73cbd83d4f7983953da81eb57cc3d886d42f094bf9f32be5d54e
sha512: 9a4b0aca2f106148d15b16809afeb66c37c7c422154ba44de83c6186929df97ecbbf7b0e2b98c23ab43f6bd85dfc1331d4e02c98cb1b4d9ef135273dcbd4c772
ssdeep: 98304:recklLyupM6AGv90FXmqw0rCZiYeRvr8p18QtuDaGIXG9VsQpzr0WmLO3VogHcQ:rJkp1DdsrZYSnQgVVsQRAWPLAJSn9OO
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkafull
ProductVersion: 1.10.28
TranslationUsa: 0x0173 0x00dc

Trojan.Win32.Eb.bmi also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AntiSandbox.GenericKD.36078134
FireEyeGeneric.mg.50dbaf0d17a0375c
McAfeeArtemis!50DBAF0D17A0
CylanceUnsafe
ZillyaTrojan.Eb.Win32.309
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.AntiSandbox.GenericKD.36078134
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_90% (D)
CyrenW32/Trojan.OYXW-4201
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Packed.Predatorthief-9820523-0
KasperskyTrojan.Win32.Eb.bmi
AlibabaTrojan:Win32/Azorult.6c65603e
AegisLabTrojan.Win32.Eb.4!c
RisingRansom.ScarletFlash!8.1142F (TFE:5:IxrZyQ9FrYU)
Ad-AwareTrojan.AntiSandbox.GenericKD.36078134
SophosMal/Generic-S
ComodoMalware@#31sojta9e3xni
F-SecureTrojan.TR/AD.GoCloudnet.xorzz
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.RULTAZO.USMANAB21
McAfee-GW-EditionBehavesLike.Win32.Ransomware.rc
EmsisoftTrojan.AntiSandbox.GenericKD.36078134 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.AntiSandbox.GenericKD.36078134
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.xorzz
MAXmalware (ai score=100)
KingsoftWin32.Hack.Undef.(kcloud)
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.AntiSandbox.Generic.D2268236
ZoneAlarmTrojan.Win32.Eb.bmi
MicrosoftTrojan:Win32/Azorult.MS!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R362771
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34780.@pKfaeHwoXgG
ALYacTrojan.AntiSandbox.GenericKD.36078134
VBA32BScope.Trojan.Azorult
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/GdSda.A
ESET-NOD32WinGo/RanumBot.J
TrendMicro-HouseCallTrojanSpy.Win32.RULTAZO.USMANAB21
TencentWin32.Trojan.Eb.Svrn
IkarusTrojan.WinGo.Ranumbot
FortinetW32/Kryptik.HGYA!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.ba055b
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM11.1.8915.Malware.Gen

How to remove Trojan.Win32.Eb.bmi?

Trojan.Win32.Eb.bmi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment