Trojan

What is “Trojan.Win32.Ekstak.alnab”?

Malware Removal

The Trojan.Win32.Ekstak.alnab is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.alnab virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.alnab?


File Info:

name: 3DA0B19AE473D73755E5.mlw
path: /opt/CAPEv2/storage/binaries/40e35d801b88f65929caea44f311a28e367cc61ded203ada19bf290523e08cdc
crc32: 5D550CC5
md5: 3da0b19ae473d73755e59cf2f0d53268
sha1: 61258857a13ec28a6fe3845327be71ce5e7bd0dd
sha256: 40e35d801b88f65929caea44f311a28e367cc61ded203ada19bf290523e08cdc
sha512: 0e1871c1c89e86bc958d3b68c7712a34b2d69aa621f5ffdaaf1ef47e34b9e97050c01195a3f72d15f35c3c26cdcb18ce68f6e5f50baf0eb443a4922d210b5e41
ssdeep: 196608:EpIHLXb8+d4o5PZftxeVCBbbV8NSRQS4oTtxev1lFh1fyYD:bXb14o5PZzeit88RQHok3jD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A486235BFF4292DED08A9C76EA2148F829F27337583450CC07B99AB64E356E0C7671D2
sha3_384: c2705cb5a98d18cb9f1644d33aef48bed6159d17fe7a3d5fa7dacaebf3c768fb340c14b98a62645783a7fe68b7d0979b
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Ecover Keys
FileDescription: Ecover Keys Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.alnab also known as:

LionicTrojan.Win32.Ekstak.4!c
CylanceUnsafe
SangforTrojan.Win32.Ekstak.gen
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CyrenW32/Ekstak.BQ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0DAQ22
KasperskyTrojan.Win32.Ekstak.alnab
AvastWin32:Adware-gen [Adw]
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
SophosMal/Generic-S
MicrosoftTrojan:Win32/Sabsik!ml
ZoneAlarmTrojan.Win32.Ekstak.alnab
GDataWin32.Backdoor.Bodelph.TNHHAO
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Adware-gen.R469588
McAfeeArtemis!3DA0B19AE473
VBA32Trojan.Ekstak
MalwarebytesAdware.DownloadAssistant
IkarusTrojan-Dropper.Win32.Agent
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Ekstak.alnab?

Trojan.Win32.Ekstak.alnab removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment