Trojan

About “Trojan.Win32.Ekstak.apmvj” infection

Malware Removal

The Trojan.Win32.Ekstak.apmvj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.apmvj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Ekstak.apmvj?


File Info:

name: 212A9FCAF1E347D6FE65.mlw
path: /opt/CAPEv2/storage/binaries/b3439bb2bd7aea36ee1a7b7e226318b4ebff4f289c64c1fdaac3eccf836d45ad
crc32: 87685C85
md5: 212a9fcaf1e347d6fe654cb7f53832bb
sha1: 700d48c3c59537c520f26e1a81c0525fc5c4717f
sha256: b3439bb2bd7aea36ee1a7b7e226318b4ebff4f289c64c1fdaac3eccf836d45ad
sha512: d169a32bc60964acb4da59c9d2bc5eac6b16c9cab99c628355a6be6ca191da77dcad8e5f443d6b7e9817f6e067d7ef7cb0ce87b51ba5caf7819b80f9bac72be5
ssdeep: 196608:k5XTgP0JBsgZBz/aDhR1wLp/E+2ycjlWXZFsOUPE5:0DEKBnXDyDmd2hlEFdUs5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16A8633D2BAC51C31E2B29CBD086B12E249397D1D0EFC7E75967D360789B9240FA06B4D
sha3_384: a609c393d8f03b7d3ef5df28ef4a112164b766a6fb248d844c8f9149cf935c9d56ff3cfa7ec5e7d578b301de7ef44dbb
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-10-31 14:04:59

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: NataLib Setup
FileVersion:
LegalCopyright:
ProductName: NataLib
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.apmvj also known as:

BkavW32.AIDetectMalware
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
Cylanceunsafe
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.apmvj
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
VaristW32/ABRisk.EGJS-0380
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Ekstak.apmvj
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
MalwarebytesAdware.DownloadAssistant
TencentWin32.Trojan.Ekstak.Bplw
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
AvastOther:Malware-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Win32.Ekstak.apmvj?

Trojan.Win32.Ekstak.apmvj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment