Trojan

Trojan.Win32.Ekstak.avyym (file analysis)

Malware Removal

The Trojan.Win32.Ekstak.avyym is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.avyym virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Ekstak.avyym?


File Info:

name: DCCAAE2E263BEA95B3C1.mlw
path: /opt/CAPEv2/storage/binaries/fbb593abff8ca72fdadb1703976deeaa15906366fcd8ffb3397ec6840dbccc3d
crc32: 121A3260
md5: dccaae2e263bea95b3c1eaa874f9b664
sha1: dd8ec2401567cffe28bbfbff0876782bc7081b78
sha256: fbb593abff8ca72fdadb1703976deeaa15906366fcd8ffb3397ec6840dbccc3d
sha512: 3c1303292839147a98a4e25cb82408336b8a9df7a4230363ab779fd09ef5fb005ec0166627aa90b052c2a230a7ce5c6886d500e5e833542a157c84c0535b1003
ssdeep: 98304:f7LdkSbAdmIqCOSqdEv/IsVekaY4sB+sxzkQgYmnWll+ghaB4RTzHdX:TLfAWDS2EX8k753xOnWlU4nF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E43633013078AAB3F3929F36D2BED51DD16B3D59B47DA81138DE0CD90B6DA99203E760
sha3_384: fbce3ee8b6a1198813d332b7ab83db2ab95aef4aefba4e89b61f2cdb6a2055225e624ef87f388d966403eb89cf31fefb
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2024-02-24 14:08:34

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: WinMount Free Setup
FileVersion:
LegalCopyright:
ProductName: WinMount Free
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.avyym also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
McAfeeArtemis!DCCAAE2E263B
Cylanceunsafe
SangforDropper.Win32.Ekstak.V1xy
AlibabaTrojanDropper:Win32/Ekstak.5511fa9b
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.avyym
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Yfow
F-SecureTrojan.TR/AD.Nekark.jksrj
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.FakeAV
VaristW32/Trojan.AVQV-2966
AviraTR/AD.Nekark.jksrj
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Ekstak.avyym
GDataWin32.Backdoor.Bodelph.XSQSLS
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Malware-gen.C5593429
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0CC224
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Ekstak.avyym?

Trojan.Win32.Ekstak.avyym removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment