Trojan

Trojan.Win32.Ekstak.avyds removal instruction

Malware Removal

The Trojan.Win32.Ekstak.avyds is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.avyds virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Created a service that was not started
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Ekstak.avyds?


File Info:

name: 9330A9483372B2654DE9.mlw
path: /opt/CAPEv2/storage/binaries/ae03fdd3803d00e10158e4a8a1808d6a2cd22ebddc346d5787cae49f3e982137
crc32: 175ABD38
md5: 9330a9483372b2654de9c18597f0ba43
sha1: 2e12d0fd0df299945f2d273f96be3dfbaaa8d11a
sha256: ae03fdd3803d00e10158e4a8a1808d6a2cd22ebddc346d5787cae49f3e982137
sha512: d3b66b77c50a30e2262fbde1a734154d40d8de9c3340538c24a0b35687343c5a9125c6b149ae3ef7d7487d87f1e0c9ff4a94c5a40c1da4ba845113a71d533939
ssdeep: 98304:I3CHHkZS3agolkAuqXLm+ijWlHggO+5yP0:SCHCOoyqb1r3v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15A16335221944EA4CC62EBF3BC3948440A463C519124B36451EFE9ECBB7D85CE6A7FF2
sha3_384: 1e7a305dcd46b573c5bf9bf17e945aae4cb048d4225180ddfa43c6740cb8018eb38cb3cc61f9e4f152b408f1fca1287d
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: VSO Inspector Setup
FileVersion:
LegalCopyright:
ProductName: VSO Inspector
ProductVersion: 2.0.2.0
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.avyds also known as:

SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
McAfeeArtemis!9330A9483372
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Agent.V3tq
AlibabaTrojanDropper:Win32/Ekstak.3c1f2ace
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Ekstak.avyds
AvastWin32:Malware-gen
TencentWin32.Trojan.Ekstak.Vimw
F-SecureTrojan.TR/Drop.Agent.pdjki
DrWebTrojan.MulDrop26.27570
TrendMicroTrojan.Win32.PRIVATELOADER.YXEBWZ
SophosMal/Generic-S
GDataWin32.Trojan.Kryptik.7TXUID
AviraTR/Drop.Agent.pdjki
KingsoftWin32.Troj.Unknown.a
ZoneAlarmTrojan.Win32.Ekstak.avyds
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/Trojan.FMUK-6726
AhnLab-V3Malware/Win.Generic.C5592586
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojan.Win32.PRIVATELOADER.YXEBWZ
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.234370683.susgen
FortinetW32/Agent.SLC!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Ekstak.avyds?

Trojan.Win32.Ekstak.avyds removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment