Trojan

Trojan.Win32.Ekstak.avacf removal tips

Malware Removal

The Trojan.Win32.Ekstak.avacf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.avacf virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Ekstak.avacf?


File Info:

name: 2E7D239A078B16D3370B.mlw
path: /opt/CAPEv2/storage/binaries/f2ca944ffeb7ab0236fc678f5c472fc388082bf5f2590be7ac0781a17200ca0a
crc32: 87531B63
md5: 2e7d239a078b16d3370b523a1523ed76
sha1: 66b46a27d721ff9a7f4b3cf062b6a11ed2daccd2
sha256: f2ca944ffeb7ab0236fc678f5c472fc388082bf5f2590be7ac0781a17200ca0a
sha512: c2c0d706d8cb1d6bf0b2e4d80181bd03bfaf8a3e93fdf233bc89f7df09890be24cb82e3f031e460f76799d7f98065ebdf2651aa974a6ace5d7cbc80adb232a7c
ssdeep: 98304:QUK4pazgvX/N5vThjTtBBr0X1dN2DK8zNGm8VuwQa39:r3vljvNEhB8zIm8VulI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188263313D6E62C79D6310F787E84B41E8B87F32336BBA030D2AD84D51B39B952E505A3
sha3_384: 8d2377bdd8520b6d9e4e556f6860eca75c6b9d9027f4c3f718f30af0a23e490e348cd67456a0febcad56075e08e54baf
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Movie clips store Setup
FileVersion:
LegalCopyright:
ProductName: Movie clips store
ProductVersion: 0.1.1.4
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.avacf also known as:

LionicTrojan.Win32.Ekstak.4!c
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
McAfeeArtemis!2E7D239A078B
MalwarebytesGeneric.Malware/Suspicious
SangforDropper.Win32.Ekstak.Vpn7
AlibabaTrojanDropper:Win32/Ekstak.a4530ceb
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Ekstak.avacf
AvastWin32:Malware-gen
TencentWin32.Trojan.Ekstak.Kcnw
F-SecureTrojan.TR/Drop.Agent.wdqgy
DrWebTrojan.Siggen23.55780
TrendMicroTROJ_FRS.0NA103B424
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
AviraTR/Drop.Agent.wdqgy
MicrosoftTrojan:Win32/ICLoader.JLK!MTB
ZoneAlarmTrojan.Win32.Ekstak.avacf
GDataWin32.Trojan.Kryptik.UHRJM0
VaristW32/Agent.ZFBR-3928
AhnLab-V3Trojan/Win.Malware-gen.R631389
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_FRS.0NA103B424
MaxSecureTrojan.Malware.223018278.susgen
FortinetW32/Agent.SLC!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Ekstak.avacf?

Trojan.Win32.Ekstak.avacf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment