Trojan

Trojan.Win32.Ekstak.amlby malicious file

Malware Removal

The Trojan.Win32.Ekstak.amlby is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.amlby virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing

How to determine Trojan.Win32.Ekstak.amlby?


File Info:

name: F9ED57DA4741CF250E29.mlw
path: /opt/CAPEv2/storage/binaries/c921d9d306d3057e4a1d27fa46782be08349a1b782213bd656636a9ddfce6afb
crc32: F3724313
md5: f9ed57da4741cf250e29678c3d8f5f8a
sha1: 153248f5d9cb8ac9fff8d15d5a1f15402a5ac945
sha256: c921d9d306d3057e4a1d27fa46782be08349a1b782213bd656636a9ddfce6afb
sha512: 337f26c6d82ce6a4792fe842dd68b746d487419bfac1ae97298c380505a453c621ed2329975fe358151446ea17a845b162632472b28f61c0d55329675322d55b
ssdeep: 196608:3u/DtCYpBmmWlgGAWC9EQdvEEsPuxSJI5N2/ORbytK:3u/DoUFWlonqag3Ns
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13476331C2DDBE62DDDE21B3EAC35485912BAD7E7EC0E171A15D88B1A8F3CAC110541EE
sha3_384: 3075e8d3681ee2721ddb2e484d8757bdffbd256003397de49e12235c8264fd707a9d8c45b16575688512a58082c3c886
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: LionMay Software
FileDescription: Everyday Auto Backup
FileVersion: 1.0.0.41
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.amlby also known as:

MicroWorld-eScanGen:Variant.Cerbu.148307
FireEyeGen:Variant.Cerbu.148307
ALYacGen:Variant.Cerbu.148307
VIPREGen:Variant.Cerbu.148307
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Ekstak.04bee625
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
KasperskyTrojan.Win32.Ekstak.amlby
BitDefenderGen:Variant.Cerbu.148307
NANO-AntivirusTrojan.Win32.Ekstak.jqxjwu
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Cerbu.148307
SophosMal/Generic-S
F-SecureTrojan.TR/Drop.Agent.zocrp
DrWebTrojan.Zadved.1709
TrendMicroTROJ_GEN.R002C0WGP22
McAfee-GW-EditionArtemis
EmsisoftGen:Variant.Cerbu.148307 (B)
GDataWin32.Backdoor.Bodelph.CHMLJ9
JiangminTrojan.Ekstak.bzmx
AviraTR/Drop.Agent.zocrp
MAXmalware (ai score=88)
ArcabitTrojan.Cerbu.D24353
ZoneAlarmTrojan.Win32.Ekstak.amlby
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R507222
McAfeeArtemis!F9ED57DA4741
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002C0WGP22
MaxSecureTrojan.Malware.185844682.susgen
AVGWin32:Adware-gen [Adw]

How to remove Trojan.Win32.Ekstak.amlby?

Trojan.Win32.Ekstak.amlby removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment