Trojan

How to remove “Trojan.Win32.Eb.bok”?

Malware Removal

The Trojan.Win32.Eb.bok is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.bok virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Eb.bok?


File Info:

crc32: A9A79D45
md5: f4f87be8fb7e4454c401a2227bea9d29
name: F4F87BE8FB7E4454C401A2227BEA9D29.mlw
sha1: e4bdb1dd7bd30f053d74b26293ea5e7a95ca82a7
sha256: a9bdb3e14f4cd26e274d6c9325ac430b6ca88e65e7a3a2cf8526db4b2ff57d91
sha512: 94d0f74cbdc1b1e9d3a2524c63fb2ceef8201c9fb0570a8cdbd53395439a10634a74c7d5ef0e4a9dc389da6df4083f225ead3916de1b5c896061246e754cafd9
ssdeep: 98304:ZmobnBLAjBDg98LxKSx8zYcvbtx7LVcml48QfcWtc3f++cR4wqTwG6xnkCZOu2Z:Zxb9qDpFjktLoM1wgwbZVX5tdUAP6yn
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkagudy
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00e1

Trojan.Win32.Eb.bok also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36125746
FireEyeGeneric.mg.f4f87be8fb7e4454
Qihoo-360Generic/HEUR/QVM11.1.9FDE.Malware.Gen
McAfeeGenericRXAA-AA!F4F87BE8FB7E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Eb.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36125746
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.d7bd30
CyrenW32/Trojan.GTBA-9250
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BotX-gen [Trj]
ClamAVWin.Packed.Bulz-9821727-0
KasperskyTrojan.Win32.Eb.bok
AlibabaTrojan:Win32/Azorult.d7fba061
RisingTrojan.Kryptik!8.8 (TFE:5:MPPpv3POZjQ)
Ad-AwareTrojan.GenericKD.36125746
SophosMal/Generic-S
ComodoMalware@#2646e686n48q7
F-SecureTrojan.TR/AD.GoCloudnet.wcoje
TrendMicroTROJ_GEN.R06CC0DAI21
McAfee-GW-EditionBehavesLike.Win32.Ransomware.rc
EmsisoftTrojan.GenericKD.36125746 (B)
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.wcoje
MAXmalware (ai score=88)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Azorult.MT!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2273C32
ZoneAlarmTrojan.Win32.Eb.bok
GDataTrojan.GenericKD.36125746
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R363323
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34760.@pKfae4Nc5cG
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32a variant of Win32/Kryptik.HIWN
TrendMicro-HouseCallTROJ_GEN.R06CC0DAI21
TencentWin32.Trojan.Eb.Efkq
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIRY!tr
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Eb.bok?

Trojan.Win32.Eb.bok removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment