Trojan

Trojan.Win32.Eb.bnl removal

Malware Removal

The Trojan.Win32.Eb.bnl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.bnl virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Eb.bnl?


File Info:

crc32: B2CE12EB
md5: a57abb60b19c7794d34812deef190cdc
name: A57ABB60B19C7794D34812DEEF190CDC.mlw
sha1: 3f6787bfdbdf2a27c8e3affe8fca5a183ec416fc
sha256: f66aaad84734a2449ebe74095557777f2ea8a5723436adcbb0ff3d0d27328d6d
sha512: 2aa97b443839977b364dade1fa17b127df5c6245f5ae349ab9bdc71a54ba34e288eb010fc1d1c51aab4e7b7523390adeac2c0ed1985f600a57f0ff4e10c24eaf
ssdeep: 98304:tbcQBxF2YQUyhB0YD1YX6CVxi6RKPV0YKtC2s0gW2sAvbPbwVTDFa6b85MnJREt:1TWh86Km2wRhjPbB2ZJoDMokU9Z6LS
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkagude
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00dc

Trojan.Win32.Eb.bnl also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45557997
FireEyeGeneric.mg.a57abb60b19c7794
CAT-QuickHealTrojan.Glupteba
McAfeeArtemis!A57ABB60B19C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.ArchSMS.lsxE
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45557997
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.0b19c7
CyrenW32/Kryptik.CXK.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Packed.Trojanx-9820164-0
KasperskyTrojan.Win32.Eb.bnl
AlibabaTrojanPSW:Win32/Predator.9376177b
ViRobotTrojan.Win32.Z.Kryptik.4496896.A
RisingTrojan.Kryptik!1.D139 (CLASSIC)
Ad-AwareTrojan.GenericKD.45557997
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1122056
DrWebTrojan.Inject4.6596
TrendMicroTROJ_GEN.R06CC0DAG21
McAfee-GW-EditionBehavesLike.Win32.Ransomware.rc
EmsisoftTrojan.GenericKD.45557997 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Eb.ka
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1122056
MicrosoftPWS:Win32/Predator.KM!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B728ED
ZoneAlarmTrojan.Win32.Eb.bnl
GDataTrojan.GenericKD.45557997
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4298515
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34780.@pKfaCKMTKgG
ALYacTrojan.GenericKD.45557997
MAXmalware (ai score=83)
VBA32BScope.Trojan.Caynamer
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HITD
TrendMicro-HouseCallTROJ_GEN.R06CC0DAG21
TencentWin32.Trojan.Kryptik.Lmas
IkarusTrojan-Downloader.Win32.SmokeLoader
FortinetW32/Kryptik.HIRY!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/Trojan.6f5

How to remove Trojan.Win32.Eb.bnl?

Trojan.Win32.Eb.bnl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment