Trojan

Trojan.Win32.Ekstak.alyol removal instruction

Malware Removal

The Trojan.Win32.Ekstak.alyol is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.alyol virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.alyol?


File Info:

name: 35C6F09CCC8007BFC2F6.mlw
path: /opt/CAPEv2/storage/binaries/85fbf97d54967736fdd92bc796cd5fff57dc98a52b8bcd028af2dd28006ac0cd
crc32: 55974AAB
md5: 35c6f09ccc8007bfc2f6bf42e8216c8e
sha1: 58c2a5a296326b7b0ca76c2d07890fa827450297
sha256: 85fbf97d54967736fdd92bc796cd5fff57dc98a52b8bcd028af2dd28006ac0cd
sha512: 57d864b62565ac574705daef4ecc73779788a73dc9bfdd79a8a393fca19b939dbbf5c6aac6a75b1fba8c41e14ca31461faa4f08edb9c7d89ed5708cb0c3fca03
ssdeep: 98304:LjUnRX7DRLAMG5qZTWJ1jHaM/S1wEAhd5pEkLc4OZzybHJUolQt9qOS:3Unl7DRL7IBwAtdLc4DHJU/Az
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15C46338054CA46BAC1FD5E361D337325503BCE7A377518B2BFC4BA9D5C6A46688C8393
sha3_384: 97ba2c2126c87f394059a633ddd185e750a9052a6266c943144c28611ef4e06004752dd2dc8b0249e3cb3ea31fb52852
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Secure Wipe
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.alyol also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanGen:Variant.Cerbu.139911
FireEyeGen:Variant.Cerbu.139911
ALYacGen:Variant.Cerbu.139911
CylanceUnsafe
SangforTrojan.Win32.Ekstak.gen
AlibabaTrojanDropper:Win32/Ekstak.792bbbee
K7GWTrojan ( 005722f11 )
K7AntiVirusTrojan ( 005722f11 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
KasperskyTrojan.Win32.Ekstak.alyol
BitDefenderGen:Variant.Cerbu.139911
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Cerbu.139911
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftGen:Variant.Cerbu.139911 (B)
GDataWin32.Backdoor.Bodelph.3VB67G
ZoneAlarmTrojan.Win32.Ekstak.alyol
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Adware-gen.R487281
McAfeeArtemis!35C6F09CCC80
MAXmalware (ai score=85)
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0DDM22
AVGWin32:Adware-gen [Adw]

How to remove Trojan.Win32.Ekstak.alyol?

Trojan.Win32.Ekstak.alyol removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment