Trojan

Trojan.Win32.Ekstak.awitq malicious file

Malware Removal

The Trojan.Win32.Ekstak.awitq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.awitq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a service that was not started
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Ekstak.awitq?


File Info:

name: 3B4BED12E34BC82CDE88.mlw
path: /opt/CAPEv2/storage/binaries/87c3418396c940262664b40cac2f26f8167f82c3d517ac1324250d5fac6ca58f
crc32: 4E66ADC1
md5: 3b4bed12e34bc82cde88174e6514d524
sha1: 8ae06e60146b1083d6ed4f51a12f99267be71ed2
sha256: 87c3418396c940262664b40cac2f26f8167f82c3d517ac1324250d5fac6ca58f
sha512: 683b0201f9ea8736a608ba13a7691c554684ed19669bb851ec21f89e28b82522ce7331f1a9d4dfc7364239ad3171e075e13e163746c05bf71c77c555405fd526
ssdeep: 49152:C9mewGcnh68LcGVquePeCF5zP3rmb4fYEqL8g4x:MRcnyGUueDr78XEGOx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122953323E2D4EC7AF19407F41D688162B65BBF483C78892633CC6DAE2D76459C71836B
sha3_384: 02a38ec0c612e51721e7cc25cdce198cdb1001b92122f3b997850efd4523ab89a958b383c4db47651a84d2ea367b18da
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Mail Sender Setup
FileVersion:
LegalCopyright:
ProductName: Mail Sender
ProductVersion: 1.3.3.3
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.awitq also known as:

BkavW32.Common.98833E37
LionicTrojan.Win32.Ekstak.4!c
CAT-QuickHealTrojan.Ekstak
MalwarebytesGeneric.Malware/Suspicious
SangforDropper.Win32.Ekstak.V6oh
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Generic.31ea7a1f
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Ekstak.awitq
AvastWin32:Malware-gen
F-SecureTrojan.TR/Drop.Agent.blfqt
DrWebTrojan.MulDrop26.35111
TrendMicroTrojan.Win32.PRIVATELOADER.YXECJZ
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
VaristW32/Trojan.WBJT-3074
AviraTR/Drop.Agent.blfqt
MicrosoftTrojan:Win32/ICLoader.JLK!MTB
ZoneAlarmTrojan.Win32.Ekstak.awitq
GDataWin32.Trojan.Kryptik.LX4Q75
AhnLab-V3Adware/Win.Malware-gen.R638346
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojan.Win32.PRIVATELOADER.YXECJZ
TencentWin32.Trojan.Ekstak.Lajl
FortinetW32/Agent.SLC!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[dropper]:Win/Ekstak.awitq

How to remove Trojan.Win32.Ekstak.awitq?

Trojan.Win32.Ekstak.awitq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment