Trojan

How to remove “Trojan.Win32.Eb.bob”?

Malware Removal

The Trojan.Win32.Eb.bob is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.bob virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Eb.bob?


File Info:

crc32: FC42D891
md5: d5b1ecfc502b277dab57a2e8be1a636a
name: D5B1ECFC502B277DAB57A2E8BE1A636A.mlw
sha1: 88ddb15507a576fa9d3af1f6317e7a18e22e2675
sha256: 2db56ed29a8ec63e35bee24568bad5464316ed7cbabdb262aa518f5ec7c74322
sha512: 41fa72495528f73665d1386ff7b24825dea3f73573a926fc2c803846dcfd511fb52a09cbde38bcb1b1ef13a73bff42ebd7eaf73af32533569e6ac623fc846c19
ssdeep: 98304:pChEAwWAagzSW0pF7JyjqVrciqo0ic4klwjHo8b7DwsK19VAZ4UqA5j1e88qufc:p0hngtmVuwkqXwJ19uaVA5ImSTtV2BO
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkagudy
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00e1

Trojan.Win32.Eb.bob also known as:

Elasticmalicious (high confidence)
ClamAVWin.Packed.Gocloudnet-9821314-0
FireEyeGeneric.mg.d5b1ecfc502b277d
McAfeeGenericRXNJ-HN!D5B1ECFC502B
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36122176
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.507a57
CyrenW32/Trojan.CEUT-2566
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Eb.bob
AlibabaTrojan:Win32/Azorult.127ef127
MicroWorld-eScanTrojan.GenericKD.36122176
RisingTrojan.Kryptik!8.8 (TFE:5:blSGgaexi2K)
Ad-AwareTrojan.GenericKD.36122176
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Ransomware.rc
EmsisoftTrojan.GenericKD.36122176 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.csb
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Azorult.MT!MTB
GridinsoftTrojan.Win32.Packed.vb
ArcabitTrojan.Generic.D2272E40
ZoneAlarmTrojan.Win32.Eb.bob
GDataTrojan.GenericKD.36122176
AhnLab-V3Malware/Gen.Reputation.C4301081
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34760.@pKfaOgJS9nG
ALYacTrojan.GenericKD.36122176
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32a variant of Win32/Kryptik.HIWN
TrendMicro-HouseCallTROJ_GEN.R002C0DAI21
TencentWin32.Trojan.Eb.Wsjp
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HIRY!tr
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.9ED3.Malware.Gen

How to remove Trojan.Win32.Eb.bob?

Trojan.Win32.Eb.bob removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment