Trojan

Should I remove “Trojan.Win32.Ekstak.alonp”?

Malware Removal

The Trojan.Win32.Ekstak.alonp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.alonp virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.alonp?


File Info:

name: EC92E286A2EE7B9A3EE3.mlw
path: /opt/CAPEv2/storage/binaries/c3e1d76694b3fb015350d9e203033af0a55dc8e7e24d3ccaff331f9d723c42f0
crc32: 140D5C30
md5: ec92e286a2ee7b9a3ee36e99cb8c84e0
sha1: fd45428dc9d9c8d0c02651bc870b1b6fdbde0251
sha256: c3e1d76694b3fb015350d9e203033af0a55dc8e7e24d3ccaff331f9d723c42f0
sha512: a007525c7cd9d9c25cc9995fcc74da0250f05c27d2a798a7f32c72b2253ead87501ce2ab414db900ec77a74b5867f5067b9b413364dda4a68e90f9cadb121b07
ssdeep: 196608:tsTe4FI8q8eY22dk/jX8a+B/FhtRJNOhX0aZ2mrD/YItyE:+S4+8v220jsdB9hL7SX0aZzDtt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144A633BDD3842CB4F12F63B1F12F275A9A236DB356601C91B985F0F16632C0A9376B25
sha3_384: 150e1de94060a29890c0e4c3236d812c9cc0e7bd113539085da40c93d155eb9f5bea5703c1f7b3acff45ae7d28eb36fc
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: CE Master LLE
FileDescription: QM Server Repair Toolbox Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.alonp also known as:

LionicTrojan.Win32.Ekstak.4!c
CylanceUnsafe
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Ekstak.BP.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.alonp
AvastWin32:Adware-gen [Adw]
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
IkarusTrojan-Dropper.Win32.Agent
GDataWin32.Backdoor.Bodelph.OWZNZE
JiangminTrojan.Ekstak.bvfi
GridinsoftRansom.Win32.Sabsik.sa
ZoneAlarmTrojan.Win32.Ekstak.alonp
MicrosoftTrojan:Win32/Tnega!ml
AhnLab-V3Adware/Win.Adware-gen.R470980
McAfeeArtemis!EC92E286A2EE
VBA32Trojan.Ekstak
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0CB722
TencentWin32.Trojan.Ekstak.Anfm
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]
MaxSecureTrojan.Malware.73555928.susgen

How to remove Trojan.Win32.Ekstak.alonp?

Trojan.Win32.Ekstak.alonp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment