Trojan

About “Trojan.Win32.Ekstak.avvbw” infection

Malware Removal

The Trojan.Win32.Ekstak.avvbw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.avvbw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Created a service that was not started
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Ekstak.avvbw?


File Info:

name: 0A4A41073032D6D2705A.mlw
path: /opt/CAPEv2/storage/binaries/51f6bc43a8a924eaf511d31515ca1f2ce91c1b314a1cc3e4c61a982443abc6a2
crc32: DA1698F9
md5: 0a4a41073032d6d2705a7fe39395841d
sha1: d76dad06b4bff9eb4392f1494974e22bf1169098
sha256: 51f6bc43a8a924eaf511d31515ca1f2ce91c1b314a1cc3e4c61a982443abc6a2
sha512: cc23a751b6ab665bd71ec94d4311e7564d4a6c4f06442f466d50f77055f2af5562776b1035555b0b62c1c22669e6033984fa1b277560bb1777d8731c7c554184
ssdeep: 49152:1q/i3dNH0jVlBY/+i/SUtfO4t81eNXjQ92ymbQoU9zzUsH4n8txyMYYaXqI/M46K:I/i3HoBYvSOueNXm2o9Y8txSYa6IxLiO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FE53322A6986D30CDD28DFE7E874D01296BFC5B6A7A7051D2EF9E0D6F3B608D005316
sha3_384: 29c52171b61126281f999a99b3a1bbf12e15fe0fe5f37a3953452deef1aab07a26893787328e3764ed48e38af28367b5
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: DVD Turbo Burn Free Setup
FileVersion:
LegalCopyright:
ProductName: DVD Turbo Burn Free
ProductVersion: 0.2.1.7
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.avvbw also known as:

BkavW32.Common.4C40D09D
LionicTrojan.Win32.Ekstak.4!c
Cylanceunsafe
SangforDropper.Win32.Agent.V56f
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Ekstak.1c614caf
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTrojan.Win32.PRIVATELOADER.YXEBQZ
KasperskyTrojan.Win32.Ekstak.avvbw
AvastWin32:Malware-gen
TencentWin32.Trojan.Ekstak.Rwhl
F-SecureTrojan.TR/Drop.Agent.ngtxc
TrendMicroTrojan.Win32.PRIVATELOADER.YXEBQZ
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
VaristW32/Trojan.YAER-0044
AviraTR/Drop.Agent.ngtxc
KingsoftWin32.Trojan.Ekstak.a
MicrosoftTrojan:Win32/ICLoader.JLK!MTB
ViRobotTrojan.Win.Z.Ekstak.3311743
ZoneAlarmTrojan.Win32.Ekstak.avvbw
GDataWin32.Trojan.Kryptik.17TCHP
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Malware-gen.R635460
MalwarebytesGeneric.Malware/Suspicious
MaxSecureTrojan.Malware.234157335.susgen
FortinetRiskware/Agent
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[dropper]:Win/Ekstak.avvbw

How to remove Trojan.Win32.Ekstak.avvbw?

Trojan.Win32.Ekstak.avvbw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment