Trojan

Trojan.Win32.Eb.bom removal tips

Malware Removal

The Trojan.Win32.Eb.bom is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.bom virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Eb.bom?


File Info:

crc32: C82B40BD
md5: 1dc83976245f4a69a98c5f4ba85f2a8b
name: 1DC83976245F4A69A98C5F4BA85F2A8B.mlw
sha1: 08aa13303341d3809506a1afe5d5fee423317cbb
sha256: efa36e429f2e048b3f168c5d12f262a9a48a2f87e554af2840a82cb016834518
sha512: 34177a5400859c1827349295f70143aac36d44427a7b683ced3e84827a9d6b6d02c11855ba4890f665822ab5e027536dd8099300dd1707dce7053fe582d583b6
ssdeep: 98304:CdhxteVJr9Z3AghINZ6lch9GerT+Inou0ecObAvHJeEetq2fD4ZtlbCcEL9jMYj:CheKaW+8ou5hmmtfgYX54/LC0boS4zd
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkagudy
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00e1

Trojan.Win32.Eb.bom also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36126177
FireEyeGeneric.mg.1dc83976245f4a69
CAT-QuickHealTrojan.Agent
McAfeeArtemis!1DC83976245F
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36126177
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_80% (D)
CyrenW32/Trojan.GYIK-4946
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BotX-gen [Trj]
ClamAVWin.Packed.Vidarstealer-9821720-0
KasperskyTrojan.Win32.Eb.bom
AlibabaTrojan:Win32/Azorult.be514ba3
AegisLabHacktool.Win32.ArchSMS.lsxE
RisingTrojan.Kryptik!1.D164 (CLASSIC)
Ad-AwareTrojan.GenericKD.36126177
SophosMal/Generic-S
ComodoMalware@#2g0yuqzepqs8a
F-SecureHeuristic.HEUR/AGEN.1122056
DrWebTrojan.DownLoader36.35481
VIPREWin32.Malware!Drop
TrendMicroTROJ_GEN.R06CC0DAI21
McAfee-GW-EditionBehavesLike.Win32.Ransomware.rc
EmsisoftTrojan.GenericKD.36126177 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1122056
MAXmalware (ai score=84)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Azorult.MT!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2273DE1
ZoneAlarmTrojan.Win32.Eb.bom
GDataTrojan.GenericKD.36126177
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4302124
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34780.@pKfaK31x3eG
ALYacTrojan.GenericKD.36126177
VBA32BScope.Trojan.Zenpack
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIVK
TrendMicro-HouseCallTROJ_GEN.R06CC0DAI21
TencentWin32.Trojan.Eb.Eclc
IkarusTrojan-Downloader.Win32.SmokeLoader
FortinetW32/Kryptik.HIRY!tr
AVGWin32:BotX-gen [Trj]
Cybereasonmalicious.03341d
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM11.1.B247.Malware.Gen

How to remove Trojan.Win32.Eb.bom?

Trojan.Win32.Eb.bom removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment