Trojan

Trojan.Dropper.EKS removal

Malware Removal

The Trojan.Dropper.EKS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Dropper.EKS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Dropper.EKS?


File Info:

name: 50151022C5DE8DE68FE2.mlw
path: /opt/CAPEv2/storage/binaries/f56fc8bf1652659de0a71f13328653ad6de7fe35d468c2a564072df589bf5ebf
crc32: 1F25DF9D
md5: 50151022c5de8de68fe2c8d1bb5ce898
sha1: 61c9db88539ee6ccb5afab45511a0f12cbc9d0f9
sha256: f56fc8bf1652659de0a71f13328653ad6de7fe35d468c2a564072df589bf5ebf
sha512: 580054535f7ff0d60533b610be609dd0a0c43d85f9dd157e5cebd39d1ac55bf217bebb3950eef84f4c74eaee03252882de41d92c485669132a45777686772ded
ssdeep: 98304:sZxm55Z1VAwxVayrAIuD5+0D3rMmnI+mc8OZ34mtWqm0:Uxm55Z1ZVaoAIQ4sMoI+YOZ34mYV0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1813633C242C9C76EC0249EF97B2BD230921734D4EEF9C6D938186A4E2F715D686D7B81
sha3_384: 146c2f1bcc201bb58ca16d0e3a1279c97f17dafe1dde93bd713f70fa0ff6fde32c247066ac0898539f971f979e1bd17b
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-12-13 14:45:42

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: RTLtacDecor Setup
FileVersion:
LegalCopyright:
ProductName: RTLtacDecor
ProductVersion: 1.2.1.3
Translation: 0x0000 0x04b0

Trojan.Dropper.EKS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
SkyhighBehavesLike.Win32.Trojan.rc
McAfeeArtemis!50151022C5DE
MalwarebytesTrojan.Dropper.EKS
CrowdStrikewin/malicious_confidence_60% (D)
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
ZillyaTrojan.Convagent.Win32.462022
GoogleDetected
VaristW32/Trojan.NQGJ-1004
PandaTrj/Genetic.gen
IkarusTrojan.Win32.Ekstak
MaxSecureTrojan.Malware.121218.susgen
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Dropper.EKS?

Trojan.Dropper.EKS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment