Trojan

Trojan.Win32.Ekstak.alnxg removal guide

Malware Removal

The Trojan.Win32.Ekstak.alnxg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.alnxg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Ekstak.alnxg?


File Info:

name: 0EB6892335865AA5F821.mlw
path: /opt/CAPEv2/storage/binaries/58297e6505fd697e017cee332003fcb68fc9d80e44dcd0ef2d10e8749b8c6e00
crc32: C683C521
md5: 0eb6892335865aa5f8213bc89d565f42
sha1: 04ab253bb71f2265b496e702fb577ab7fa9f1ba6
sha256: 58297e6505fd697e017cee332003fcb68fc9d80e44dcd0ef2d10e8749b8c6e00
sha512: 4e8a079d2767d01f907d20abeb59afd08d9143dd19c1ab7ae3bd604c5c01ff96ca78705a2ee2a41579974da9741987647d9a236fdd7a9e24517e1c326a4f6680
ssdeep: 196608:0ncT1h+p3DNVuPNsmQRdqnVjVNu9rUP8dtxXSXv/0oE4i+HamNulARmqW9Oxk:QGhNPNs1GnMo8dz2pE4iEaEmck
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8A6233FB268643ED5AA4B3145B39310597BBBA1A91A8C2F0BF0491DCF275701E3F616
sha3_384: ecd2bdb740fc8924945893b6feaef8edfeb6332796f2789995ffad770ec63ce24de9f888e3393e08e810b483f942a614
ep_bytes: 558bec83c4a453565733c08945c08945
timestamp: 2020-03-14 17:59:41

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Ile Master LLD
FileDescription: Ord Repair Toolbox Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Ord Repair Toolbox
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.alnxg also known as:

CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
K7AntiVirusTrojan ( 005722fe1 )
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
KasperskyTrojan.Win32.Ekstak.alnxg
AvastWin32:Adware-gen [Adw]
ZillyaTrojan.Ekstak.Win32.59649
WebrootW32.Adware.Downloadassistant
MicrosoftTrojan:Script/Phonzy.C!ml
ZoneAlarmTrojan.Win32.Ekstak.alnxg
GDataWin32.Trojan.BSE.1KA5L9G
CynetMalicious (score: 100)
McAfeeArtemis!0EB689233586
MalwarebytesAdware.DownloadAssistant
APEXMalicious
TencentWin32.Trojan.Ekstak.Jmk
AVGWin32:Adware-gen [Adw]

How to remove Trojan.Win32.Ekstak.alnxg?

Trojan.Win32.Ekstak.alnxg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment