Trojan

Trojan.Win32.Ekstak.amrrj removal instruction

Malware Removal

The Trojan.Win32.Ekstak.amrrj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.amrrj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Deletes executed files from disk

How to determine Trojan.Win32.Ekstak.amrrj?


File Info:

name: EF75C4B41C119FE7000D.mlw
path: /opt/CAPEv2/storage/binaries/3df830d901179788447f97403b99040857fde67b88b069a7cec4f55110ddab6a
crc32: 6168F26B
md5: ef75c4b41c119fe7000d4553fee9a7cc
sha1: 7491d808a6af0dfd2921ded74924586128cf3825
sha256: 3df830d901179788447f97403b99040857fde67b88b069a7cec4f55110ddab6a
sha512: 742066806a1835e9f0ca16db178c49609d3a73eca1432a56bdfdec1f21d65bd0132b40c362ee65040c6c99baf1436e95523f7a4dc2a68fb76c37a04529e3b29d
ssdeep: 98304:ki+H9FTzgVpQ+gJqYRHiWDfBNin3gS08ugpPhqFmkQYwJKPbCPcdnJHNYYC2XgNr:l+3TaQ+yqeHhWwSSFmkxzeinpvC+gcN2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DC46333203CF5834C6F71A795DB477C116AEBE6598B6431EAD2C241F1A82DE05E1B38B
sha3_384: d9f46233fb11bdde8dc5db37ed773d78272bf376bec42b47428dd40cfde3092bb5b5f7f87df60d08764c047ba2aa6ee9
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: File cloner
FileVersion: 0.0.0.0
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.amrrj also known as:

LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
ClamAVWin.Malware.Ekstak-9968247-0
McAfeeArtemis!EF75C4B41C11
CylanceUnsafe
SangforDropper.Win32.Ekstak.Voe3
AlibabaTrojanDropper:Win32/Ekstak.edc0fc2b
K7GWTrojan ( 005722f11 )
K7AntiVirusTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Ekstak.amrrj
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan.Ekstak.Qgil
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataWin32.Backdoor.Bodelph.AHLWRX
JiangminTrojan.Ekstak.cbqn
AviraTR/AD.Nekark.fmbjr
MicrosoftTrojan:Win32/Wacatac.A!ml
AhnLab-V3Adware/Win.Adware-gen.R514141
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0DI122
FortinetW32/Agent.SLC!tr
AVGWin32:Adware-gen [Adw]

How to remove Trojan.Win32.Ekstak.amrrj?

Trojan.Win32.Ekstak.amrrj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment