Trojan

Trojan.Win32.Ekstak.aiovp malicious file

Malware Removal

The Trojan.Win32.Ekstak.aiovp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.aiovp virus can do?

  • Unconventionial language used in binary resources: Slovenian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Ekstak.aiovp?


File Info:

name: B232C2F26233736D8AD5.mlw
path: /opt/CAPEv2/storage/binaries/c86ca99101dc804fe0caee6351611bc016a6d0f90f20764c52aa03ab76badfb1
crc32: 4E62B08E
md5: b232c2f26233736d8ad5ed6396bc206f
sha1: 69ca0967c9218a7b4d7fbce1d6bf7e7f4d420703
sha256: c86ca99101dc804fe0caee6351611bc016a6d0f90f20764c52aa03ab76badfb1
sha512: eab67a667ab9d9e134dfc31fc20754abf2e88e22f10f4e1cd06694d0737c0174ab65d62309c5cf9dab2d692ef766ec9df5492e22cdb62df139757c3c0f9794be
ssdeep: 49152:4wPc8HT8ksqzJgZ8caicI3ES6/9P3gQxR3nW4y0FVV1HQSed:464Meqcaw3jc3gqRXdFPJs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T148F5F11193A78051CA914B30483BEFF062FE6DB55B30AA7B33A5FDDABD721D16D21122
sha3_384: c860f1205cad6fcc5d80885ab188aa4410f8d9d1ca7aada0727cfe7867f865ad959dd8d51fbe5fc22eb64e0dbba630af
ep_bytes: 558bec6aff687046640068c030640064
timestamp: 2020-10-31 17:51:50

Version Info:

CompanyName: the sz development
FileDescription: Howard
FileVersion: 1.6.9.1
InternalName: Howard
LegalCopyright: Copyright © 2013-2019
LegalTrademarks:
OriginalFilename: Howard.exe
ProductName: the sz development Howard
ProductVersion: 1.6.9.1
Translation: 0x0407 0x04b0

Trojan.Win32.Ekstak.aiovp also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Midie.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71146
FireEyeGeneric.mg.b232c2f26233736d
CAT-QuickHealTrojan.WacatacPMF.S16651368
ALYacTrojan.GenericKDZ.71146
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2644388
SangforTrojan.Win32.Wacatac.C
K7AntiVirusTrojan ( 0056252b1 )
AlibabaTrojan:Win32/Ekstak.3a589d14
K7GWTrojan ( 0056252b1 )
Cybereasonmalicious.262337
CyrenW32/Kryptik.CKH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HAWC
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Adwarex-9785905-0
KasperskyTrojan.Win32.Ekstak.aiovp
BitDefenderTrojan.GenericKDZ.71146
NANO-AntivirusTrojan.Win32.Kryptik.ibcjfz
AvastWin32:AdwareX-gen [Adw]
Ad-AwareTrojan.GenericKDZ.71146
SophosMal/Generic-S + Troj/Agent-BEQV
DrWebTrojan.Zadved.1659
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftTrojan.GenericKDZ.71146 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1142521
Antiy-AVLTrojan/Generic.ASMalwS.30FD141
MicrosoftTrojan:Win32/Tnega.MS!MTB
ZoneAlarmHEUR:Trojan-Downloader.Win32.Razy.gen
GDataTrojan.GenericKDZ.71146
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.ICLoader.R354579
McAfeeGenericRXMP-GA!B232C2F26233
MAXmalware (ai score=80)
VBA32BScope.Trojan.Zadved
MalwarebytesMalware.AI.2480169014
RisingTrojan.Kryptik!1.AA23 (CLOUD)
YandexTrojan.Kryptik!pr88rKwK55Y
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GZFR!tr
AVGWin32:AdwareX-gen [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.Win32.Ekstak.aiovp?

Trojan.Win32.Ekstak.aiovp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment