Trojan

How to remove “Trojan.Win32.Ekstak.amnpz”?

Malware Removal

The Trojan.Win32.Ekstak.amnpz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.amnpz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A file with an unusual extension was attempted to be loaded as a DLL.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Likely virus infection of existing system binary
  • Deletes executed files from disk

How to determine Trojan.Win32.Ekstak.amnpz?


File Info:

name: 74435AAA25973F08AB12.mlw
path: /opt/CAPEv2/storage/binaries/c384fb30d9ba9dc79e7a5809bdcd0c80a33aa5cc0971e4140e70fd969d1f9026
crc32: 4D3CABC6
md5: 74435aaa25973f08ab1212bf84533d29
sha1: bbe1eb16ff01e6a1695358eea76fb4409f789bc9
sha256: c384fb30d9ba9dc79e7a5809bdcd0c80a33aa5cc0971e4140e70fd969d1f9026
sha512: 78e0c81585ae8c065e3bcbec2f019da246d1c979bf33066d8994e5252736823b34e007368009529f07dae0d84f7e727e91574e8d92c0707680e9af1510829ed4
ssdeep: 98304:5irSNuUfEn2DAWSehXI9UE2p6Sa+Rkox5ddeVcLTLVfs4+Ey:o2NuEEnmAW9I9URpZaoxFlVfs4+Ey
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B416333BDF792078F29681B8A828C067DF72BD107925530D5EDCD1AD3E703640AA77A9
sha3_384: ba9549c377b9fbc53b49588fd93c26b17df910d44a504dc81f7f7ff4e9cad02c7fc4954e42f4fb9de5eda02fec03401e
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: DeleteFiles Pro Setup
FileVersion:
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.amnpz also known as:

LionicTrojan.Win32.Ekstak.4!c
McAfeeArtemis!74435AAA2597
CylanceUnsafe
AlibabaTrojanDropper:Win32/MalwareX.15ba8571
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
ClamAVWin.Trojan.Filerepmalware-9961371-0
KasperskyTrojan.Win32.Ekstak.amnpz
AvastWin32:MalwareX-gen [Trj]
McAfee-GW-EditionArtemis!Trojan
GDataWin32.Backdoor.Bodelph.QZ4JP1
JiangminTrojan.Ekstak.cago
AviraTR/Drop.Agent.nxpjq
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
CynetMalicious (score: 99)
AhnLab-V3Downloader/Win.Generic.C5219836
TrendMicro-HouseCallTROJ_GEN.R002H0CH622
FortinetW32/Agent.SLC!tr.dldr
AVGWin32:MalwareX-gen [Trj]

How to remove Trojan.Win32.Ekstak.amnpz?

Trojan.Win32.Ekstak.amnpz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment