Trojan

About “Trojan.Win32.Ekstak.alncl” infection

Malware Removal

The Trojan.Win32.Ekstak.alncl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.alncl virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.alncl?


File Info:

name: AAF8A59D35866E6486B4.mlw
path: /opt/CAPEv2/storage/binaries/93e455a77cb00931dd6752069c9baca8f5770684945d9eb875097cf9c2c2bde0
crc32: E7FF4181
md5: aaf8a59d35866e6486b47ae073a4d1d9
sha1: 74026fdd69b78aff1a984f42d08b0edc8a38afed
sha256: 93e455a77cb00931dd6752069c9baca8f5770684945d9eb875097cf9c2c2bde0
sha512: 020b6d76b31a15998141c413538c3f35e64c061e4afefc6e8fd5b86439fd6a90f97bf5f4c47a02e188a25f9707636afbad6654a337009fc860e82f31c27c6081
ssdeep: 196608:ErbuRE7bb6hAmlaeEmQ2hESshv+2ySlfQsGTEe4NXXBYNM31fyYD:guS7X6ls1IKW2y+fQsGTET/YNMjD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10886239BAF4186EED1969C76EA3549F91CF7B237047400CC07BADAAA0D352E1C6530E3
sha3_384: 5095a3f3a46139399f1deee86a7102c9a9ac9a011a2e3b08c1115e1092d84b5bf3694f3b4b0c9013141763607d0ad276
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Cover Keys
FileDescription: Cover Keys Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.alncl also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanGen:Variant.Cerbu.129100
ALYacGen:Variant.Cerbu.129100
CylanceUnsafe
SangforTrojan.Win32.Ekstak.gen
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CyrenW32/Ekstak.BQ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
KasperskyTrojan.Win32.Ekstak.alncl
BitDefenderGen:Variant.Cerbu.129100
AvastWin32:Adware-gen [Adw]
EmsisoftGen:Variant.Cerbu.129100 (B)
TrendMicroTROJ_GEN.R053C0WB222
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
FireEyeGen:Variant.Cerbu.129100
SophosMal/Generic-S
WebrootW32.Malware.Gen
MicrosoftTrojan:Win32/Sabsik!ml
GDataGen:Variant.Cerbu.129100
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Adware-gen.R469588
McAfeeArtemis!AAF8A59D3586
MAXmalware (ai score=85)
VBA32Trojan.Ekstak
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R053C0WB222
TencentWin32.Trojan.Ekstak.Lqyq
IkarusTrojan-Dropper.Win32.Agent
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Ekstak.alncl?

Trojan.Win32.Ekstak.alncl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment