Trojan

How to remove “Trojan.Win32.Ekstak.avrdd”?

Malware Removal

The Trojan.Win32.Ekstak.avrdd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.avrdd virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Created a service that was not started
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Ekstak.avrdd?


File Info:

name: 1E1DB7BA7C0327279E41.mlw
path: /opt/CAPEv2/storage/binaries/75fe8980de4fa25acfa68618cd668979178f8ae2def8b22f8d0821191575c78c
crc32: 8A5A1832
md5: 1e1db7ba7c0327279e4174176a35d619
sha1: 1aae4bacba23bc599183299eb9e26ce3df6a3851
sha256: 75fe8980de4fa25acfa68618cd668979178f8ae2def8b22f8d0821191575c78c
sha512: aaad62cf5a06818b8a5c3f900ad91bea8e2429f02df2b600cc558cef63d5254aa741a30efbe6c59e5411611e46481ad7d9cd4e870728c14443e72cefe97e2379
ssdeep: 196608:r0MhrqX811DKh9afyevbzs/kYsiqaC4nDUVxJC8hC4W8z:rT5qX8jQ/kziqwnDUVxJJC4lz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1137633072B7309B6E91664B51CD0450B3A4EBF66397763D673CCBC588A6F2F6A880F44
sha3_384: 070a21fc459a81f07e1559c79480ad7a83f2b28c3bd15f37de5f6448ca2501370284eef1c8ada064fed283638fb84c05
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: jUlia DVD Creator Setup
FileVersion:
LegalCopyright:
ProductName: jUlia DVD Creator
ProductVersion: 0.2.1.0
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.avrdd also known as:

LionicTrojan.Win32.Ekstak.4!c
SkyhighBehavesLike.Win32.ObfuscatedPoly.wc
Cylanceunsafe
SangforDropper.Win32.ICLoader.Va1f
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Ekstak.b09ee277
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Ekstak.avrdd
NANO-AntivirusTrojan.Win32.Ekstak.kiylmf
AvastWin32:Malware-gen
TencentWin32.Trojan.Ekstak.Nqil
F-SecureTrojan.TR/ICLoader.lsswg
DrWebTrojan.MulDrop25.21989
TrendMicroTrojan.Win32.PRIVATELOADER.YXEBKZ
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
VaristW32/Trojan.QSXF-0670
AviraTR/ICLoader.lsswg
KingsoftWin32.Trojan.Ekstak.a
MicrosoftTrojan:Win32/ICLoader.JL!MTB
ZoneAlarmTrojan.Win32.Ekstak.avrdd
GDataWin32.Trojan.Kryptik.S7F9WW
AhnLab-V3Malware/Win.Malware-gen.C5587257
McAfeeArtemis!1E1DB7BA7C03
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojan.Win32.PRIVATELOADER.YXEBKZ
MaxSecureTrojan.Malware.233144415.susgen
FortinetW32/Agent.SLC!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Ekstak.avrdd?

Trojan.Win32.Ekstak.avrdd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment