Trojan

How to remove “Trojan.Win32.Ekstak.amimy”?

Malware Removal

The Trojan.Win32.Ekstak.amimy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.amimy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.amimy?


File Info:

name: FB76306AC0C8766C3C1F.mlw
path: /opt/CAPEv2/storage/binaries/d1ab9c2eee8b785a9ca98e11c03176ac0655c93096cd6416c9d8cc349e7a4689
crc32: 2D9CE9F3
md5: fb76306ac0c8766c3c1f4f21127010c7
sha1: ec1b9ef54587b14f8eeca3b160cb8cc930b7971a
sha256: d1ab9c2eee8b785a9ca98e11c03176ac0655c93096cd6416c9d8cc349e7a4689
sha512: 2fcdc9ffd508b4583ddee0450de0cc698cf65b9b6512ce2a54e27a447da6d1dc6b797826fe754612e524911d7ad1498ddc76664b5b92aea1edaa5feeb74f008f
ssdeep: 196608:WoZe3BRCvL3a0qlI5r8zr3Wyg5x+TVsLEu:ze3XCvja0q4r8H3Rg5xYsj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C66335AF3211137C1928FB4AD5A29DF5A7FFEC51A7A280F70D8371E163B9212D44AB0
sha3_384: 3635af82ea2963ae1649fbc5164a73baeae2634b8e4242e6e1ca348285faa491d83abd63bcb8b918baa63ca4124b243d
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Bisvip, LLC
FileDescription: Bisvip Disk Cleaner Free
FileVersion: 1.2.0.19
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.amimy also known as:

MicroWorld-eScanTrojan.GenericKD.39879146
FireEyeTrojan.GenericKD.39879146
CylanceUnsafe
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.3d1135e5
K7GWTrojan ( 005722f11 )
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.amimy
BitDefenderTrojan.GenericKD.39879146
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan-dropper.Agent.Efas
Ad-AwareTrojan.GenericKD.39879146
SophosMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.39879146 (B)
GDataWin32.Backdoor.Bodelph.KL6NI9
JiangminTrojan.Ekstak.bysa
ArcabitTrojan.Generic.D26081EA
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!FB76306AC0C8
MAXmalware (ai score=86)
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0DFQ22
AVGWin32:Adware-gen [Adw]

How to remove Trojan.Win32.Ekstak.amimy?

Trojan.Win32.Ekstak.amimy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment