Trojan

What is “Trojan.Win32.Ekstak.almyl”?

Malware Removal

The Trojan.Win32.Ekstak.almyl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.almyl virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.almyl?


File Info:

name: 213365D7FD1F74A33BF7.mlw
path: /opt/CAPEv2/storage/binaries/a080cd083d8cc0198d184fbe8f5d86367966a87fd69626889b8f8c2a4bae5da5
crc32: 845E7BCD
md5: 213365d7fd1f74a33bf775da92e115f2
sha1: fd6d0e7bf44b49d6715485892a39b2820f63b28e
sha256: a080cd083d8cc0198d184fbe8f5d86367966a87fd69626889b8f8c2a4bae5da5
sha512: 50705c67d408052dbcd39a82354ef4a4db8625a98533dab16be5eee64eed4d3d44058e1cb74e54705d92b29b9455bca49b67a73af4f84688dd92c9d77a0fc90f
ssdeep: 196608:ErluHcA1sP8D8NPNwx17lrWP+FLhau/G1fyYD:kk8A1FD8Po1Jrs+CcGjD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B86335BBF40D7EAC4999C76EA3540F828F276332A2455DC07B997B60D342E0CB671E2
sha3_384: cd534755918622e863ddb297b86dbfd05ab4aa6de3609af4f52744f710400a2e124ea2b7f30f57c3c661125540bfad06
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Ecover Keys
FileDescription: Ecover Keys Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.almyl also known as:

SangforTrojan.Win32.Ekstak.almyl
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CyrenW32/Ekstak.BQ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0DAQ22
KasperskyTrojan.Win32.Ekstak.almyl
AvastWin32:Adware-gen [Adw]
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
SophosMal/Generic-S
MicrosoftTrojan:Win32/Sabsik!ml
ZoneAlarmTrojan.Win32.Ekstak.almyl
GDataWin32.Backdoor.Bodelph.R6EOA7
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Adware-gen.R469588
McAfeeArtemis!213365D7FD1F
MalwarebytesAdware.DownloadAssistant
TencentWin32.Trojan.Ekstak.Hnkt
IkarusTrojan-Dropper.Win32.Agent
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Ekstak.almyl?

Trojan.Win32.Ekstak.almyl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment