Trojan

What is “Trojan.Win32.Ekstak.amayo”?

Malware Removal

The Trojan.Win32.Ekstak.amayo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.amayo virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.amayo?


File Info:

name: 4CFD1F2194D68202F71B.mlw
path: /opt/CAPEv2/storage/binaries/ebd946117ad87a8afe50a757d87a1ae87e33510669b27426da24643bf5afcf1e
crc32: 8A677DB0
md5: 4cfd1f2194d68202f71ba93e26786a76
sha1: 7316f0d4b8709820971c9c91623f6ba1b29f61b4
sha256: ebd946117ad87a8afe50a757d87a1ae87e33510669b27426da24643bf5afcf1e
sha512: ab4e2a790b0351029ceb98019dcfb66ac0831bea6b42e5a6911d3ede31a9b7d29bd93d7baad1113e090018e4d558e7b37da9141c12200bc0145277e98e98b062
ssdeep: 196608:gTCKgFKwulAtOf9iyNv1YeGnIfDnOMvJIGvmAEu4DLpCZgWF3+JQg:DKjvlg+FqGDnOMvS/TwzOH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7A6334378D085F3DE50A438F8DEC79030F6A77A5B6AE5AC26E9DDCB4942BB04507B18
sha3_384: 697af9944c4f3c8a720250ce92752f121dcc79858f589a2fab1d663aa8828adc92e5e77fec7a2136092e8c6142567e8e
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: Syney
FileDescription: Syney PC Cleaner Setup
FileVersion:
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.amayo also known as:

Elasticmalicious (moderate confidence)
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0DEA22
KasperskyTrojan.Win32.Ekstak.amayo
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan-dropper.Agent.Piav
EmsisoftAdware.Downloader (A)
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataWin32.Backdoor.Bodelph.Z4IOGB
McAfeeArtemis!4CFD1F2194D6
MalwarebytesAdware.DownloadAssistant
APEXMalicious
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]

How to remove Trojan.Win32.Ekstak.amayo?

Trojan.Win32.Ekstak.amayo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment