Trojan

How to remove “Trojan.Win32.Ekstak.alnhr”?

Malware Removal

The Trojan.Win32.Ekstak.alnhr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.alnhr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.alnhr?


File Info:

name: 7350F725097F4615FE3E.mlw
path: /opt/CAPEv2/storage/binaries/575caefbd29987fcc815dc3f5a53e07829952f085b519dc2ef02d379b98b58eb
crc32: 5969C521
md5: 7350f725097f4615fe3eb5d4991205c0
sha1: 1ce92cd07911b79ebe385a39326509d0afa1d60f
sha256: 575caefbd29987fcc815dc3f5a53e07829952f085b519dc2ef02d379b98b58eb
sha512: 9873819cd8144577ea169942dbfa0628f4e17689a7cdfee86ed30011ea87fcfe1815d4a2127f2ae105c8ec8bc011cb168c5b73324b5f33f957a82e119d04a761
ssdeep: 196608:Eni6apmcC52EAFxpyzACNqTp4XaiGYnRn3nvy1fyYD:j6xb2xTpycD4GYRn3vyjD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F786235BBF4197EED5898C76EA3148F92CF67232097460CC17B9AABA0D346E0C7271D1
sha3_384: 3055e4a1d5900937b3f9c2a6ee14527212abc7f58d8e88b4e570e997ee6f00bf6f7ddc2d5c90a812778e613456038058
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: VerA Keys
FileDescription: VerA Keys Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.alnhr also known as:

MicroWorld-eScanGen:Variant.Cerbu.129389
FireEyeGen:Variant.Cerbu.129389
McAfeeArtemis!7350F725097F
CylanceUnsafe
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CyrenW32/Ekstak.BQ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0DAR22
KasperskyTrojan.Win32.Ekstak.alnhr
BitDefenderGen:Variant.Cerbu.129389
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan.Ekstak.Afrc
EmsisoftGen:Variant.Cerbu.129389 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Sabsik!ml
ZoneAlarmTrojan.Win32.Ekstak.alnhr
GDataGen:Variant.Cerbu.129389
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Adware-gen.R469588
ALYacGen:Variant.Cerbu.129389
MalwarebytesAdware.DownloadAssistant
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A

How to remove Trojan.Win32.Ekstak.alnhr?

Trojan.Win32.Ekstak.alnhr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment