Trojan

About “Trojan.Win32.Ekstak.alobb” infection

Malware Removal

The Trojan.Win32.Ekstak.alobb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.alobb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.alobb?


File Info:

name: 4B3319AC97FAFB011428.mlw
path: /opt/CAPEv2/storage/binaries/441394b288536338813a59c3299f10af9033a48733ec939d5cc92f9a5d060ca3
crc32: BB8DACE9
md5: 4b3319ac97fafb01142853734fb99331
sha1: 731affda3fe9992fc118894fd5a07a60a6501f5f
sha256: 441394b288536338813a59c3299f10af9033a48733ec939d5cc92f9a5d060ca3
sha512: 919f8d65028217bd9d2e7e2a57002b51148d0689dd5db181ec6d2c1fc1ce0c3b8950671b94108c48e019b48ff8f0aded0a98f8f3f735d5fdae7afd78d9a63750
ssdeep: 196608:qHFaPpssgDXYzyEWUpKES8S+KPsG2k+bn4Yc+ectd3KWOxe:CzRXU89LF2fw+ew3+e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3A6233FB268653ED96F5B3205B39350597BBA62B91A8C1F07F0480DDF228711E3B616
sha3_384: 2f52baf18ad4b46e60b47f12d54a82af085bd478a5dc02f64b6826e34e2ec7baa7eee99cf8d528b5d6fffdaaab09726d
ep_bytes: 558bec83c4a453565733c08945c08945
timestamp: 2020-03-14 17:59:41

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Ilg Master LLD
FileDescription: Orf Repair Toolbox Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Orf Repair Toolbox
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.alobb also known as:

LionicTrojan.Win32.Sheladl.4!c
FireEyeTrojan.GenericKD.38833349
CAT-QuickHealTrojan.Ekstak
ALYacTrojan.GenericKD.38833349
CylanceUnsafe
ZillyaTrojan.Ekstak.Win32.59649
SangforTrojan.Win32.Ekstak.alobb
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0CB622
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.alobb
BitDefenderTrojan.GenericKD.38833349
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10d01210
EmsisoftTrojan.GenericKD.38833349 (B)
McAfee-GW-EditionBehavesLike.Win32.PUP.tc
SophosMal/Generic-S
GDataWin32.Trojan.BSE.1KA5L9G
Antiy-AVLTrojan/Generic.ASMalwS.35220EB
GridinsoftRansom.Win32.Sabsik.sa
ZoneAlarmTrojan.Win32.Ekstak.alobb
MicrosoftTrojan:Win32/Tnega!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R472932
McAfeeArtemis!4B3319AC97FA
VBA32Trojan.Ekstak
MalwarebytesAdware.DownloadAssistant
APEXMalicious
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Ekstak.alobb?

Trojan.Win32.Ekstak.alobb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment