Trojan

What is “Trojan.Win32.Ekstak.alojm”?

Malware Removal

The Trojan.Win32.Ekstak.alojm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.alojm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.alojm?


File Info:

name: 3C8D62498996EFDF783D.mlw
path: /opt/CAPEv2/storage/binaries/c8f9a0ab7186afcb223dd5232a53aa5793f49564c43611454dee433833f03f1a
crc32: B22354A7
md5: 3c8d62498996efdf783df50676d28259
sha1: ed2ad1f177c9bd462dbc57c9246ef6605c5f46a3
sha256: c8f9a0ab7186afcb223dd5232a53aa5793f49564c43611454dee433833f03f1a
sha512: 5f775f373be97ec509aaa1345164bb7470c9fc23dc78734c7249c374561e4714d1cf23f5f9618c49c4ca37dcb4028b114e52bf3f8caa75fe734c1cf4644f77c5
ssdeep: 196608:tgILCTBIsmvGR7ZhCRQhb/ceMurYIBhydC7PEg0+30HsZA+9HlcYhVUJlNtyE:jLS6lvmn4Q5ceMukIBuKPEgzEHQlphQ5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140A633417B78E171DC1A63B2642FE93F1A10FEA47B7A8A1F0FD4B1194DB98451A3F221
sha3_384: 96fd59792a8b35c2e5aa3502cff32c6e8d886c3e7225750bce6e9d68b347f4f9c3c9d0a0aad38a3322cd44421f87c275
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: File Master LLC
FileDescription: SQL Server Repair Toolbox Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.alojm also known as:

MicroWorld-eScanGen:Variant.Cerbu.129899
FireEyeGen:Variant.Cerbu.129899
MalwarebytesAdware.DownloadAssistant
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CyrenW32/Ekstak.BP.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0CB522
KasperskyTrojan.Win32.Ekstak.alojm
BitDefenderGen:Variant.Cerbu.129899
AvastWin32:Trojan-gen
TencentWin32.Trojan.Ekstak.Lmlh
Ad-AwareGen:Variant.Cerbu.129899
EmsisoftGen:Variant.Cerbu.129899 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Cerbu.129899
AhnLab-V3Adware/Win.Adware-gen.R470980
McAfeeArtemis!3C8D62498996
MAXmalware (ai score=89)
VBA32Trojan.Ekstak
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen

How to remove Trojan.Win32.Ekstak.alojm?

Trojan.Win32.Ekstak.alojm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment