Trojan

Trojan.Win32.Eb.box information

Malware Removal

The Trojan.Win32.Eb.box is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.box virus can do?

  • At least one process apparently crashed during execution
  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Eb.box?


File Info:

crc32: F9CAB3E2
md5: 470a1f5c8fd987d506720b4869dfbcc1
name: 470A1F5C8FD987D506720B4869DFBCC1.mlw
sha1: 113e4b24581c1ce65e49c12665f78d79d313caa3
sha256: 9d5a3e60951e3800c97635c739ae48da167cceafb9182df5837bd249a7381b7b
sha512: 932ef1547b935d3e27e0062ccce652fce4dd3188c83a07812e74a938357fcc46cb5c464d530aad637f3790c5223491fa95f36cc782677d3ee1e4c2a31c04f997
ssdeep: 98304:RmG/k6Y38mMwHU4yWoGawpBKPmf+Zj3ryeIV3i6LPTymITgvnmN8ZSIEXGaIC+P:46L0HUPMaXjGeIL7I9CZiMxfQYClg
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkagude
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00e1

Trojan.Win32.Eb.box also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45524647
FireEyeGeneric.mg.470a1f5c8fd987d5
CAT-QuickHealTrojan.IGENERIC
McAfeeGenericRXNK-MM!470A1F5C8FD9
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45524647
K7GWRiskware ( 0040eff71 )
CyrenW32/Trojan.OHZJ-6613
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Vidarstealer-9821720-0
KasperskyTrojan.Win32.Eb.box
AlibabaTrojan:Win32/Azorult.c058fe3c
RisingTrojan.Kryptik!8.8 (TFE:5:G4gcofMQ0SD)
Ad-AwareTrojan.GenericKD.45524647
EmsisoftTrojan.GenericKD.45524647 (B)
F-SecureHeuristic.HEUR/AGEN.1122056
DrWebTrojan.PWS.Stealer.26952
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DAL21
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1122056
MicrosoftTrojan:Win32/Azorult.MU!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B6A6A7
AegisLabTrojan.Win32.Eb.trF0
ZoneAlarmTrojan.Win32.Eb.box
GDataWin32.Trojan.RanumBot.VLMBBZ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R363517
Acronissuspicious
VBA32Backdoor.Mokes
ALYacTrojan.GenericKD.45524647
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32a variant of Win32/Kryptik.HIYB
TrendMicro-HouseCallTROJ_GEN.R002C0DAL21
TencentWin32.Trojan.Eb.Palu
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.HIRY!tr
BitDefenderThetaGen:NN.ZexaF.34780.@pKfaC1FxqjG
AVGWin32:BotX-gen [Trj]
AvastWin32:BotX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Generic/HEUR/QVM11.1.AEB5.Malware.Gen

How to remove Trojan.Win32.Eb.box?

Trojan.Win32.Eb.box removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment