Trojan

How to remove “Trojan.Win32.Ekstak.awadr”?

Malware Removal

The Trojan.Win32.Ekstak.awadr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.awadr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Created a service that was not started
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Ekstak.awadr?


File Info:

name: 24FC92B091E098E4954F.mlw
path: /opt/CAPEv2/storage/binaries/a6125cb9b4320120d8aa9cf565018a5ff49423b2b7820a642447ec3819c0f493
crc32: 45F89665
md5: 24fc92b091e098e4954fed07119fafba
sha1: a05dfd95702042121980152067aa4aa24c1d3730
sha256: a6125cb9b4320120d8aa9cf565018a5ff49423b2b7820a642447ec3819c0f493
sha512: b6c7f0c8a13289ce069cad02b755354b04057c852a96b687607d469aec7a06d72fdc374ae8b10f625bf5eb34903d519c6cee817c029cb18addde78cc8a1cbb03
ssdeep: 49152:1q6FjSxn1t+eD3OHFLRgdNgqkoo3/bAGQqAGzz/LzN19cm5XKKr6Ryb23S09:I6ExnzV3AN6Qq6vWGzDL15xFMH3Sm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4D533B3835108FEFD6592B62F264D280B37FE4218319039359D89FC5B6792563293EB
sha3_384: 0570aecc6089582eaf49b78ef65112cda3df521e6bf4882ebbd172d6f9add857229ed99de5073af196d7ea269c7f4150
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Menu Setup
FileVersion:
LegalCopyright:
ProductName: Menu
ProductVersion: 4.2.2.56
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.awadr also known as:

BkavW32.Common.BF610749
LionicTrojan.Win32.Ekstak.4!c
Cylanceunsafe
SangforDropper.Win32.Ekstak.V4ri
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Ekstak.e56fb183
K7GWTrojan ( 005722fe1 )
K7AntiVirusTrojan ( 005722fe1 )
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTrojan.Win32.SOCKSSYSTEMZ.YXEBZZ
KasperskyTrojan.Win32.Ekstak.awadr
AvastWin32:Malware-gen
TencentWin32.Trojan.Ekstak.Iflw
GoogleDetected
F-SecureTrojan.TR/Drop.Agent.ytwah
DrWebTrojan.MulDrop26.29228
TrendMicroTrojan.Win32.SOCKSSYSTEMZ.YXEBZZ
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
VaristW32/Trojan.AXGP-1588
AviraTR/Drop.Agent.ytwah
MicrosoftTrojan:Win32/ICLoader.JL!MTB
ZoneAlarmTrojan.Win32.Ekstak.awadr
GDataWin32.Trojan.Kryptik.PS9B86
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Generic.C5593940
MalwarebytesTrojan.Dropper
PandaTrj/Chgt.AD
MaxSecureTrojan.Malware.234496201.susgen
FortinetRiskware/Agent
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Ekstak.awadr?

Trojan.Win32.Ekstak.awadr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment