It could be a false positive for some rules. Please check EveBox Events for details. You may report problems with a signature at the link on the top right evebox page.
The trojan category should NOT be set to Block.
IMO, the only “safe” categories to block are:
ET-botcc.portgrouped
ET-botcc
ET-ciarmy
ET-compromised
ET-drop
ET-dshield
Categories that can be blocked in most networks:
ET-emerging-activex
ET-emerging-attack_response
ET-emerging-dos
ET-emerging-exploit
ET-emerging-malware
ET-emerging-netbios
The rest set to alert.