Trojan

Should I remove “Trojan.Win32.Ekstak.awmtv”?

Malware Removal

The Trojan.Win32.Ekstak.awmtv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.awmtv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Ekstak.awmtv?


File Info:

name: 55D0764E2E98DBC4D469.mlw
path: /opt/CAPEv2/storage/binaries/b30d1f1a69fa9ca438b02e71fa63bee2452978c64443ef447f56a62d66f76e00
crc32: CCC2C1CB
md5: 55d0764e2e98dbc4d46988074a8a40cd
sha1: ce6ed0023aeceb808fb78af058997a30504f28a2
sha256: b30d1f1a69fa9ca438b02e71fa63bee2452978c64443ef447f56a62d66f76e00
sha512: 1f3a4670ed1a0d403af127bd6487d13a30b31100de294141188706d8de90c0782b7bae77d875eb2f5f33c16854927418a71f0bb6e5f9ea1389014394d3cefd64
ssdeep: 98304:kx0YZTQcDaQkgI1Me8agLAqVuNwYN9ctCTXOEPRrZsW3zn7ITIZTQi4GGdsq3:i0YxQgPkn1Me8HLcNNftFPRO+fwIZTQN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1001633077742B738E211C236CC5CA1A6DA42A93769BCAE5A164DEDDC875F349C7EC380
sha3_384: 7a3d277dc6e090039c485fed2219f3d519b9b0cec53c7e5dc5a42a1dbc383a21ddd7c2e552ed25e179804d20bb3f5bd5
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2024-03-16 00:17:26

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Code Lobster Free Console Setup
FileVersion:
LegalCopyright:
ProductName: Code Lobster Free Console
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.awmtv also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
AVGOther:Malware-gen [Trj]
SkyhighBehavesLike.Win32.BadFile.rc
MalwarebytesAdware.DownloadAssistant
SangforTrojan.Win32.Agent.Vgks
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 99)
APEXMalicious
AvastOther:Malware-gen [Trj]
KasperskyTrojan.Win32.Ekstak.awmtv
F-SecureHeuristic.HEUR/AGEN.1373347
Trapminesuspicious.low.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Backdoor.Bodelph.HXVV07
AviraHEUR/AGEN.1373347
ZoneAlarmTrojan.Win32.Ekstak.awmtv
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/ABRisk.TWMB-2504
AhnLab-V3Malware/Win.Generic.C5601756
McAfeeArtemis!55D0764E2E98
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0ACF24
IkarusTrojan.Win32.Krypt
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Ekstak.awmtv?

Trojan.Win32.Ekstak.awmtv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment