Trojan

Should I remove “Trojan.Win32.Ekstak.alnny”?

Malware Removal

The Trojan.Win32.Ekstak.alnny is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.alnny virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.alnny?


File Info:

name: 2454A3B03A693AE0D059.mlw
path: /opt/CAPEv2/storage/binaries/dfda90203bcd62291366f20bb693f101cd80e4b156e7a7f3172dace901ecf273
crc32: 941C3458
md5: 2454a3b03a693ae0d059d6b124f28d88
sha1: 629c9b52f2a6df6c066269f64f43f8ca0c8cad73
sha256: dfda90203bcd62291366f20bb693f101cd80e4b156e7a7f3172dace901ecf273
sha512: 244662194945211ec46b8833c39a4ebe1761f390af643c58a5ab4ffafd15ad96b7533ee4525a0273e61e666a86407d3c1714866d412d184b8d7aac11fcbd7488
ssdeep: 196608:EfhcfbSN7I0S35oXVM1+6QHkvOgkfZmzxX454lJqZrMxwC11fyYD:kFG3Qq1ckjkgzy5sMJM71jD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19086235BBF01A3EED0479C75EA2145F51CF6723A1830659C1BB68AFA0D352E1C76B0E2
sha3_384: 285bbfca3047f2dc946ba75c819a63c7a68ab5b6865888c52737687eb2ea32f6e2aee714aac2ed78fbec91a2f0b2109b
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: VerC Keys
FileDescription: VerC Keys Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.alnny also known as:

McAfeeArtemis!2454A3B03A69
CylanceUnsafe
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CyrenW32/Ekstak.BQ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0DAS22
KasperskyTrojan.Win32.Ekstak.alnny
AvastWin32:Adware-gen [Adw]
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
GDataWin32.Backdoor.Bodelph.I0V413
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1219006
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Adware-gen.R469588
MalwarebytesAdware.DownloadAssistant
TencentWin32.Trojan.Ekstak.Hpia
IkarusTrojan-Dropper.Win32.Agent
FortinetMalicious_Behavior.SB
AVGWin32:Adware-gen [Adw]

How to remove Trojan.Win32.Ekstak.alnny?

Trojan.Win32.Ekstak.alnny removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment