Trojan

Trojan.Win32.Ekstak.amwqi removal guide

Malware Removal

The Trojan.Win32.Ekstak.amwqi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.amwqi virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing

How to determine Trojan.Win32.Ekstak.amwqi?


File Info:

name: 25B6A4199F7C13E72934.mlw
path: /opt/CAPEv2/storage/binaries/e9f11feddaabb5fd2c52e6c71c17476271bae16acf9609ca73ffdd6780b3f520
crc32: 7A4B5D1D
md5: 25b6a4199f7c13e729343ab2ed9409a3
sha1: c1683feac57cf1570505a2b0b86cf4e2c764ed5e
sha256: e9f11feddaabb5fd2c52e6c71c17476271bae16acf9609ca73ffdd6780b3f520
sha512: ce1abe39e36701853f982dc5872efc294d570700ad4aa3b7ecfde58c676f0b92afbb9c9e764f55f093792c3a4fae1bc01846200d342302b6624b7f7ca50dd907
ssdeep: 196608:ZU24ZaA8eYABPcf8MPMu+VqdoRYi/LV/ESZpbDm:7ZeYQc0UgYWRt/hDfm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1386633E773D7C075CB5284722D4268AA6A777E3A2F7A1D9E6D0E5C4F90336824B0C1B0
sha3_384: 0eef3465ed4c70e5ee8ed56e0c049edfa18c0c65455181d9d3207be274abef9c967faf8e8e530785c4f586ec2d1aceec
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: 43delite
FileDescription: Uplicate Picture Finder Setup
FileVersion:
LegalCopyright:
ProductName: Uplicate Picture Finder
ProductVersion: 1.0.6.43
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.amwqi also known as:

CylanceUnsafe
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
KasperskyTrojan.Win32.Ekstak.amwqi
AvastFileRepMalware [Adw]
DrWebTrojan.Zadved.1716
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataWin32.Backdoor.Bodelph.XKIK5H
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!25B6A4199F7C
MalwarebytesMalware.AI.58578330
TrendMicro-HouseCallTROJ_GEN.R002H0DJ922
TencentWin32.Trojan.Dropper.Vsmw
FortinetW32/Agent.SLC!tr
AVGFileRepMalware [Adw]

How to remove Trojan.Win32.Ekstak.amwqi?

Trojan.Win32.Ekstak.amwqi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment