Trojan

Should I remove “Trojan.Win32.Ekstak.aloba”?

Malware Removal

The Trojan.Win32.Ekstak.aloba is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.aloba virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.aloba?


File Info:

name: CC3D5A264B8C3F04D3A2.mlw
path: /opt/CAPEv2/storage/binaries/3f3e85ba931e7db008c5229a515766079413f1f07abacdb87e5a4408e9377747
crc32: FB46D621
md5: cc3d5a264b8c3f04d3a2655948c878e5
sha1: 9de0d8f08357d5dc59383c39f810eed1597e3aad
sha256: 3f3e85ba931e7db008c5229a515766079413f1f07abacdb87e5a4408e9377747
sha512: b0f5480c774ceb9714e26c6e1c5c271d6efc9f9903a4b7399d728530e29f0c03eb9095af2fa65ff1e3fd7dd41168a1225992666daa29a0a599486533284a450d
ssdeep: 196608:PHFaPpssgDXYzyEWUpKES8S+PYz0C70Mhj0YUjjjYcOxe:/zRXU89Q+F7D10bjjc1e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10FA6233FB368653EC9AA1B7245B39750597BBA61A41A8C2F07F0090DCF278711F3B616
sha3_384: 764db404b4f5e3ad5f85318bfdeb8bc3d5b8c0791a830bbc847d65ab2abd6771cd1957c58d92a9b3d87126dd57686b2b
ep_bytes: 558bec83c4a453565733c08945c08945
timestamp: 2020-03-14 17:59:41

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Ilg Master LLD
FileDescription: Orf Repair Toolbox Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Orf Repair Toolbox
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.aloba also known as:

LionicTrojan.Win32.Ekstak.4!c
FireEyeTrojan.GenericKD.38840142
CAT-QuickHealTrojan.Ekstak
ALYacTrojan.GenericKD.38840142
CylanceUnsafe
ZillyaTrojan.Ekstak.Win32.59649
SangforTrojan.Win32.Ekstak.aloba
K7AntiVirusTrojan ( 005722fe1 )
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0DAV22
KasperskyTrojan.Win32.Ekstak.aloba
BitDefenderTrojan.GenericKD.38840142
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10d01210
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftTrojan.GenericKD.38840142 (B)
APEXMalicious
GDataWin32.Trojan.BSE.1KA5L9G
Antiy-AVLTrojan/Generic.ASMalwS.351EB4C
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R472932
McAfeeArtemis!CC3D5A264B8C
VBA32Trojan.Ekstak
MalwarebytesAdware.DownloadAssistant
AVGWin32:Adware-gen [Adw]
PandaPUP/DownloadAssistant
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Ekstak.aloba?

Trojan.Win32.Ekstak.aloba removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment