Trojan

About “Trojan.Win32.Ekstak.amswe” infection

Malware Removal

The Trojan.Win32.Ekstak.amswe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.amswe virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing

How to determine Trojan.Win32.Ekstak.amswe?


File Info:

name: 9060742376C60E1BDE03.mlw
path: /opt/CAPEv2/storage/binaries/b362c15c4ad7a4a65cb80841ec3806e8dde0cb15883f8ee674236daba4b28344
crc32: 7A84F068
md5: 9060742376c60e1bde033e103c179f8e
sha1: d5a425cdb1e3c0062011460ee91f645de9190f9f
sha256: b362c15c4ad7a4a65cb80841ec3806e8dde0cb15883f8ee674236daba4b28344
sha512: cd51639c3557929c16998442e50389ed0d7bd0853c68fbaa8ab1564474bf494c91df2153543fbabbfa186c55762ab3c3cc94e1c92f1fe49bb102ffd5e5c65d70
ssdeep: 196608:cDRxY0R3DIALkECLZggm1oJewEldKWQ37HcnVrxMV3szVnx:cDRfsGbcZZYoiKWQg323szNx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D963383256F51A1F9A5A53D0FFC5B37D17C1F832820C486A1AF97D8E5382E7CD68286
sha3_384: 20856f325cb099fceae3c294623cd6f91c8339234d063be29d95175d3519ae41d06ee78d139bbb613602728ce8b70040
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: Acgbyte, Inc.
FileDescription: Acgbyte Utilities Setup
FileVersion:
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.amswe also known as:

LionicTrojan.Win32.Ekstak.4!c
CylanceUnsafe
SangforTrojan.Win32.Agent.V1pm
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Generic.acff4daa
K7GWTrojan ( 005722fe1 )
CyrenW32/Ekstak.DA.gen!Eldorado
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.amswe
AvastWin32:Malware-gen
McAfee-GW-EditionArtemis!Trojan
GDataWin32.Backdoor.Bodelph.FGE1KZ
JiangminTrojan.Ekstak.cbzt
GoogleDetected
AviraTR/Drop.Agent.grcmc
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!9060742376C6
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0DIB22
FortinetW32/Agent.SLC!tr
AVGWin32:Malware-gen

How to remove Trojan.Win32.Ekstak.amswe?

Trojan.Win32.Ekstak.amswe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment