Trojan

Trojan.Win32.Eb.bof removal

Malware Removal

The Trojan.Win32.Eb.bof is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.bof virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Eb.bof?


File Info:

crc32: 5EFCE962
md5: 909adad7d429197eb3b613b27b40adb6
name: 909ADAD7D429197EB3B613B27B40ADB6.mlw
sha1: 2878e6f34e9fae736f5230e177ff4c8a73e9c7c4
sha256: 8c441d07d58d4f2e07a4d6ee747bf4804b51f45076407d5f93216df047755f9b
sha512: ef970273059ae76928be2fc767c2e80865108b8cf6310dc34b514eb164cec15608e826d5c284393be7c5116670e9ad5dbeb944a80072a116fdc8b94e7f5fe3f2
ssdeep: 98304:bPJitYH5Iy7A0MpP6VkQmxFy4d1NU1i2ep59WNRelGihu/XNv+7rfC3cdfH06sc:lgSip5p331Hpp3WNRSgo7e3EfH0lyUO
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkagudy
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00e1

Trojan.Win32.Eb.bof also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36123112
FireEyeGeneric.mg.909adad7d429197e
ALYacTrojan.GenericKD.36123112
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 005762f91 )
BitDefenderTrojan.GenericKD.36123112
K7GWTrojan ( 005762f91 )
Cybereasonmalicious.34e9fa
BitDefenderThetaGen:NN.ZexaF.34760.@pKfayASWDgG
CyrenW32/Trojan.WEXL-3347
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIWN
APEXMalicious
AvastWin32:BotX-gen [Trj]
ClamAVWin.Packed.Bulz-9821727-0
KasperskyTrojan.Win32.Eb.bof
AlibabaTrojan:Win32/Azorult.48b8129d
RisingTrojan.Kryptik!8.8 (TFE:5:blSGgaexi2K)
Ad-AwareTrojan.GenericKD.36123112
EmsisoftTrojan.GenericKD.36123112 (B)
F-SecureTrojan.TR/AD.GoCloudnet.davdp
TrendMicroTROJ_GEN.R002C0DAI21
McAfee-GW-EditionBehavesLike.Win32.Ransomware.rc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
JiangminTrojan.Eb.jh
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.davdp
MAXmalware (ai score=82)
KingsoftWin32.Troj.Eb.b.(kcloud)
MicrosoftTrojan:Win32/Azorult.MT!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D22731E8
AhnLab-V3Malware/Win32.Generic.C4302019
ZoneAlarmTrojan.Win32.Eb.bof
GDataTrojan.GenericKD.36123112
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXAA-AA!909ADAD7D429
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
TrendMicro-HouseCallTROJ_GEN.R002C0DAI21
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIRY!tr
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.9F5F.Malware.Gen

How to remove Trojan.Win32.Eb.bof?

Trojan.Win32.Eb.bof removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment