Trojan

Trojan.Win32.Ekstak.allzy removal tips

Malware Removal

The Trojan.Win32.Ekstak.allzy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.allzy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.allzy?


File Info:

name: 42FE9E848A88D142C045.mlw
path: /opt/CAPEv2/storage/binaries/955c1ab5809d1b8ad6677b178e64b7fcc56e7f5a787ed5a5418ad7d5933011bf
crc32: 4B15397F
md5: 42fe9e848a88d142c045d4f212767914
sha1: 40012321c45770de4939f8cdb1c7610f5b9e2e33
sha256: 955c1ab5809d1b8ad6677b178e64b7fcc56e7f5a787ed5a5418ad7d5933011bf
sha512: 079a0bca06908bbb1d00208f8a29cc4cfc42a2a0d143c586eee1fe33570b72c1b5c905b4d5bd936ba2a6024141794d9eff00a523763a523707126f5028a93d8f
ssdeep: 98304:f08lycOmg613v6YNpvWlnLyl1WGL4uUcknjV4QVtNZIsfZAXxdsWSfI2nwSKp:ln3LN5WNc1lLhRMjVhNZlfgSjnXY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1375633524B61ABB0EC7A63FA3875AC0D50723F9D0A6835284C4CB75BB9F53A47C67702
sha3_384: 7449d9d7463fad6ba42274f4ab6756b0bace4b8f6d8163222ab57da4f4603d35b0768b3e6fe36250cf167c6991d3bc70
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Akajlo Software
FileDescription: DD Catalog Professional Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.allzy also known as:

MicroWorld-eScanTrojan.GenericKD.38707057
FireEyeTrojan.GenericKD.38707057
McAfeeArtemis!42FE9E848A88
CylanceUnsafe
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CyrenW32/Agent.DZH.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R067C0WAP22
Paloaltogeneric.ml
ClamAVWin.File.Conduit-9936952-0
KasperskyTrojan.Win32.Ekstak.allzy
BitDefenderTrojan.GenericKD.38707057
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan.Ekstak.Pegk
SophosMal/Generic-S
TrendMicroTROJ_GEN.R067C0WAP22
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftTrojan.GenericKD.38707057 (B)
JiangminTrojan.Ekstak.bvdy
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ViRobotTrojan.Win32.Z.Ekstak.6242941
ZoneAlarmTrojan.Win32.Ekstak.allzy
GDataTrojan.GenericKD.38707057
AhnLab-V3Trojan/Win.Generic.C4924833
VBA32Trojan.Ekstak
ALYacTrojan.GenericKD.38707057
MalwarebytesAdware.DownloadAssistant
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.73555928.susgen
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Ekstak.allzy?

Trojan.Win32.Ekstak.allzy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment