Trojan

Trojan.Win32.Eb.btr removal guide

Malware Removal

The Trojan.Win32.Eb.btr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.btr virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Uzbek (Cyrillic)
  • The binary likely contains encrypted or compressed data.
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Eb.btr?


File Info:

crc32: 0028E7E1
md5: 971dcd0dbcd6a3a4e621829c2b005fc5
name: 971DCD0DBCD6A3A4E621829C2B005FC5.mlw
sha1: fdbf5b8b16f02bc8e578d7f41f4f6a55cfa34b44
sha256: 0c34811112a2724bc628fd45334fb86e9704082cc6da47a0136ece9f03d06d2f
sha512: 4131dbc7158e6c6184de0b69a097419946a5b8557f77488b87cba4738883193f5412b38c7bd474b4c46b9e643158048629fa19d18fb206af8cc255fff8a55443
ssdeep: 98304:vtdEQ827WiGDX/wqhFLc7fua3mRJp/ydjRLYh:vtaRf5fa7mjO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersions: 7.0.0.25
LegalCopyrights: Wsegda
ProductVersions: 67.0.20.45
Translation: 0x0409 0x067b

Trojan.Win32.Eb.btr also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00577c391 )
LionicTrojan.Win32.Eb.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AntiSandbox.GenericKDS.36336233
CAT-QuickHealTrojan.GenericRI.S18686277
ALYacTrojan.AntiSandbox.GenericKDS.36336233
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2904874
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.AntiSandbox.GenericKDS.36336233
K7GWTrojan ( 00577c391 )
Cybereasonmalicious.dbcd6a
CyrenW32/Trojan.FWF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HJLC
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Eb.btr
AlibabaTrojanDropper:Win32/Tnega.24c56673
NANO-AntivirusTrojan.Win32.Eb.ilmnbf
TencentWin32.Trojan.Eb.Hrov
Ad-AwareTrojan.AntiSandbox.GenericKDS.36336233
SophosMal/Generic-S
ComodoMalware@#2g1m28zi9qj68
F-SecureTrojan.TR/Crypt.XPACK.Gen3
BitDefenderThetaGen:NN.ZexaF.34294.2tW@aWM!VySG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Lockbit.wc
FireEyeGeneric.mg.971dcd0dbcd6a3a4
EmsisoftTrojan.AntiSandbox.GenericKDS.36336233 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen3
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.EB
ArcabitTrojan.AntiSandbox.GenericS.D22A7269
GDataTrojan.AntiSandbox.GenericKDS.36336233
AhnLab-V3Malware/Gen.RL_Reputation.R366244
McAfeePacked-GBE!971DCD0DBCD6
MAXmalware (ai score=87)
VBA32BScope.Trojan.Azorult
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTrojan.Win32.GLUPTEBA.SMD.hp
RisingTrojan.Kryptik!1.D2DF (CLASSIC)
YandexTrojan.Eb!hyfvWOq8QmE
IkarusTrojan.WinGo.Ranumbot
MaxSecureTrojan.Malware.114287702.susgen
FortinetW32/Kryptik.HJPF!tr
PandaTrj/GdSda.A

How to remove Trojan.Win32.Eb.btr?

Trojan.Win32.Eb.btr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment