Trojan

Trojan.Win32.Ekstak.jgvl malicious file

Malware Removal

The Trojan.Win32.Ekstak.jgvl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.jgvl virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

cubeload.ru

How to determine Trojan.Win32.Ekstak.jgvl?


File Info:

crc32: 3D364084
md5: c888a5ff6f21538ed5cb5cde5aedc895
name: C888A5FF6F21538ED5CB5CDE5AEDC895.mlw
sha1: 113ebe8da14c9330cd8104f407ff969e47efe589
sha256: 5f78bd6ca3c45a8c7a85966fa596268a20fe0abd814407d5d69137cf81fa5185
sha512: 71c94f827729955c2117663b658bc08b46999d854d09010fd16083f85257e10aee5cc4bd6274d38ef17bd5723cb2b99a9a70236feca0f16fa9d07510e480815d
ssdeep: 49152:cU7JgJGyQdcs0igcY6MR9pYjEbPGn4J1TeMVwKFoZUxZGoEdb:ngJXKT0iBiRPbPGnfMtsoEdb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: AJRepair.exe
FileDescription: ZX Components 4.63 installer
FileVersion: 15.1.1242.13
OriginalFilename: AJRepair.exe
ProductVersion: 15.1.1242.13
Translation: 0x0409 0x04b0

Trojan.Win32.Ekstak.jgvl also known as:

K7AntiVirusTrojan ( 0053e8521 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3673
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Ekstak.S3560696
ALYacGen:Variant.Kryptic.9
AlibabaTrojan:Win32/Ekstak.c63993ae
K7GWTrojan ( 0053e8521 )
Cybereasonmalicious.f6f215
CyrenW32/ICloader.BR.gen!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GLER
APEXMalicious
AvastWin32:ICLoader-X [Adw]
KasperskyTrojan.Win32.Ekstak.jgvl
BitDefenderGen:Variant.Kryptic.9
NANO-AntivirusTrojan.Win32.InstallCube.fijysg
MicroWorld-eScanGen:Variant.Kryptic.9
TencentWin32.Trojan.Ekstak.Szlg
Ad-AwareGen:Variant.Kryptic.9
SophosGeneric PUA BB (PUA)
ComodoApplication.Win32.ICLoader.GS@84429a
BitDefenderThetaGen:NN.ZexaF.34294.Os0@aK8OnYei
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PKJ21
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.c888a5ff6f21538e
EmsisoftGen:Variant.Kryptic.9 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/ICLoader.Gen8
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.28283CE
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Kryptic.9
AhnLab-V3PUP/Win32.ICLoader.R238310
Acronissuspicious
McAfeePacked-FME!C888A5FF6F21
VBA32BScope.Trojan.InstallCube
MalwarebytesAdware.ICLoader.Generic
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PKJ21
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!9tj5vKrMzRs
IkarusPUA.ICLoader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:ICLoader-X [Adw]
Paloaltogeneric.ml

How to remove Trojan.Win32.Ekstak.jgvl?

Trojan.Win32.Ekstak.jgvl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment