Trojan

Trojan.Win32.Ekstak.amlnr removal

Malware Removal

The Trojan.Win32.Ekstak.amlnr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.amlnr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A file with an unusual extension was attempted to be loaded as a DLL.
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Possible date expiration check, exits too soon after checking local time
  • Terminates another process
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Transacted Hollowing
  • Collects and encrypts information about the computer likely to send to C2 server
  • Likely virus infection of existing system binary

How to determine Trojan.Win32.Ekstak.amlnr?


File Info:

name: F433E95F072CCC614756.mlw
path: /opt/CAPEv2/storage/binaries/9cd23395decd13b2728c70f37e69a928a910a7966fd418c34cc72b19936c836d
crc32: F2CCC1F9
md5: f433e95f072ccc61475621761a2ea795
sha1: a7df9e8879ec01437780d84fb7590e750a8d7f32
sha256: 9cd23395decd13b2728c70f37e69a928a910a7966fd418c34cc72b19936c836d
sha512: b3372eb19618d09847a84e2fda5d740e0181b5576dc57202172cc172c1d4a89f9a846e79489cae2e2d974ab07de2d87e35c665ed64fb777ca061760ab4f67964
ssdeep: 196608:f99KKwRemc311UJ5+rSZ8bSXt29bGq4c5onLo77NAHsi:6JReX1SJMro8bSd29iiQLQAHV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T143763361FE648835F4690E300C779C814BA3E9AE07F5229B62FEFB8525DF0216F85536
sha3_384: 1eee98c1b05cae7832d76210f12fb1761fe095d93ce36975665e7e945cffdac6a97f61a6cb2cb923d5eed64231ed9b29
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: LionMaz Software
FileDescription: Everyday Auto Backup
FileVersion: 1.0.0.37
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.amlnr also known as:

LionicTrojan.Win32.Ekstak.4!c
DrWebTrojan.Zadved.1709
MicroWorld-eScanGen:Variant.Cerbu.148497
ALYacGen:Variant.Cerbu.148497
VIPREGen:Variant.Cerbu.148497
SangforTrojan.Win32.Agent.Vzom
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Ekstak.d724c501
K7GWTrojan ( 005722fe1 )
CyrenW32/Ekstak.CI.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0CGM22
KasperskyTrojan.Win32.Ekstak.amlnr
BitDefenderGen:Variant.Cerbu.148497
NANO-AntivirusTrojan.Win32.Ekstak.jraifb
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Cerbu.148497
EmsisoftGen:Variant.Cerbu.148497 (B)
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Cerbu.148497
GDataGen:Variant.Cerbu.148497
JiangminTrojan.Ekstak.bzmx
AviraTR/Drop.Agent.hsvzh
ArcabitTrojan.Cerbu.D24411
ZoneAlarmTrojan.Win32.Ekstak.amlnr
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R507222
McAfeeArtemis!F433E95F072C
MalwarebytesAdware.DownloadAssistant
MAXmalware (ai score=84)
MaxSecureTrojan.Malware.186154193.susgen
FortinetW32/Agent.SLC!tr.dldr
AVGWin32:Adware-gen [Adw]

How to remove Trojan.Win32.Ekstak.amlnr?

Trojan.Win32.Ekstak.amlnr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment