Trojan

About “Trojan.Win32.Ekstak.alndy” infection

Malware Removal

The Trojan.Win32.Ekstak.alndy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.alndy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.alndy?


File Info:

name: 3A34132607F44C0CCB50.mlw
path: /opt/CAPEv2/storage/binaries/2e2f55b822529ac9f95900903540c7ebdea034f081c384d5221cc45395b5f368
crc32: 7F6F28D4
md5: 3a34132607f44c0ccb502fe041bb4713
sha1: eee7d78ae7b5a02f51568a35bf16e6d85acaedd9
sha256: 2e2f55b822529ac9f95900903540c7ebdea034f081c384d5221cc45395b5f368
sha512: 6a1e8773cae4722ab96f68b444db4eac9cca88551bfe0122a51d5b6f242d222c980d19ee04a9a7b0b7a160ac83220150dbcdd783516f87a9e31d80c4794c0977
ssdeep: 196608:Ejni+8g7D6fQjGXyDQTxJC4HjiFPgeC7pH5oN+l8YLEqO1fyYD:WX8mDm4yKPgF5oN+uYobjD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13386236BAF8183DDD2479C72E92188F95CF67673093464DC17B98ABA0D346E1C7270E2
sha3_384: 2f2f6d15f4b027ba57776ea82a54d9055595b5f89ff630297f09f857ab183fca6e84a76c382a9740567427b02a31226f
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Cover Keys
FileDescription: Cover Keys Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.alndy also known as:

MicroWorld-eScanGen:Variant.Cerbu.129100
FireEyeGen:Variant.Cerbu.129100
ALYacGen:Variant.Cerbu.129100
CylanceUnsafe
SangforTrojan.Win32.Ekstak.alndy
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0DAQ22
KasperskyTrojan.Win32.Ekstak.alndy
BitDefenderGen:Variant.Cerbu.129100
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan.Ekstak.Ljua
Ad-AwareGen:Variant.Cerbu.129100
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
EmsisoftGen:Variant.Cerbu.129100 (B)
GDataGen:Variant.Cerbu.129100
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Adware-gen.R469588
McAfeeArtemis!3A34132607F4
MAXmalware (ai score=83)
VBA32Trojan.Ekstak
MalwarebytesAdware.DownloadAssistant
IkarusTrojan-Dropper.Win32.Agent
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Ekstak.alndy?

Trojan.Win32.Ekstak.alndy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment