Trojan

What is “Trojan.Win32.Ekstak.aloux”?

Malware Removal

The Trojan.Win32.Ekstak.aloux is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.aloux virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.aloux?


File Info:

name: C10F02E45FDD09F8835D.mlw
path: /opt/CAPEv2/storage/binaries/2929e5c77617a9a30d1011b2712c5bc4b97e800cb14ff7e79427a10dd902c574
crc32: 63A15790
md5: c10f02e45fdd09f8835da91bbb74d47b
sha1: f725eb4d65e7a49494d37a2c3b686a489680bf29
sha256: 2929e5c77617a9a30d1011b2712c5bc4b97e800cb14ff7e79427a10dd902c574
sha512: 72fcbf7aa517883ed54ea17bc96c5d87364afc0d748cb5213455b7476f1cf64c7943f232cbce761da647aa1b0f4d4ff656f96ec945315f6e9728f017fee35a85
ssdeep: 196608:pJzBwog9hlvS4LO6duH49JvTQXELY9Foup5guSzrOQOG38zlL:BjglvGg/vTQULktSzxOG0L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB9633325C284932D552E932A98F04D7C586FAFB65346126726CC7CD3F1EF043AAABD4
sha3_384: 757deac9ab6bc7369a9192434f035916b4737dbd66f9165dd4e040a88bf6cb6148c550c9bccb8e4cf116482533580455
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Company TKF
FileDescription: Smart File Delete Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.aloux also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanGen:Variant.Cerbu.129903
FireEyeGen:Variant.Cerbu.129903
CylanceUnsafe
K7AntiVirusTrojan ( 005722fe1 )
K7GWTrojan ( 005722fe1 )
ArcabitTrojan.Cerbu.D1FB6F
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.aloux
BitDefenderGen:Variant.Cerbu.129903
AvastWin32:Trojan-gen
TencentWin32.Trojan.Ekstak.Sttv
Ad-AwareGen:Variant.Cerbu.129903
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.BadFile.rc
EmsisoftGen:Variant.Cerbu.129903 (B)
IkarusTrojan-Dropper.Win32.Agent
WebrootW32.Trojan.Dropper
AviraHEUR/AGEN.1219006
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmTrojan.Win32.Ekstak.aloux
GDataWin32.Backdoor.Bodelph.JJR12L
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Adware-gen.R471264
McAfeeArtemis!C10F02E45FDD
MAXmalware (ai score=85)
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0CB722
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen

How to remove Trojan.Win32.Ekstak.aloux?

Trojan.Win32.Ekstak.aloux removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment