Trojan

About “Trojan.Win32.Ekstak.nvxw” infection

Malware Removal

The Trojan.Win32.Ekstak.nvxw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.nvxw virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Ekstak.nvxw?


File Info:

name: AC5C0840CE4197AB8708.mlw
path: /opt/CAPEv2/storage/binaries/18658f0601ce8af20a24141b3c1499aae184416ddbe834e4bb2f83ea55e6675c
crc32: 05F25F5E
md5: ac5c0840ce4197ab87086c4c0a6ee810
sha1: 4c30b018bb774b455ef6392af2146884f0f48a85
sha256: 18658f0601ce8af20a24141b3c1499aae184416ddbe834e4bb2f83ea55e6675c
sha512: a2c63aedee6d034da25f21b862b085f3d36a78b0e9544f1dd23038de260a30232ab3ee79cf8b57eeac2fe414157027dcbdbc687924437df47b3f1c7cce515808
ssdeep: 3072:QKSAEbalxNW1oaaCUK7pBghMjDDDDQpGMUnVI1kOWXZVyTarERccD7Y:QpNeloJVRD/cAMUVSkOMV8Gu7Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E524DF029A018928F71D0F311956F9E488A59D3C28E0F68FF67CBD3A78B21875A7714F
sha3_384: e081610a48fcc87d1c76b2c0f6acf2df00c21ba881487672749d5e658bff811412e4568c6af7a358778e5a89d149a77c
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2013-10-15 11:01:41

Version Info:

0: [No Data]

Trojan.Win32.Ekstak.nvxw also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen5.60190
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
FireEyeGeneric.mg.ac5c0840ce4197ab
CAT-QuickHealTrojan.Urelas.C.mue
McAfeeObfuscated-FAHQ!hb
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0048c72d1 )
AlibabaTrojanSpy:Win32/Ekstak.64b455f3
K7GWSpyware ( 0048c72d1 )
Cybereasonmalicious.0ce419
BitDefenderThetaGen:NN.ZexaF.34294.nmraaigqdjai
CyrenW32/A-351ea3cc!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.CardSpy.NAF
TrendMicro-HouseCallTROJ_URELAS_GI080278.UVPM
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Ekstak.nvxw
BitDefenderGen:Heur.Mint.SP.Urelas.1
NANO-AntivirusTrojan.Win32.CardSpy.dkjoul
SUPERAntiSpywareTrojan.Agent/Gen-CardSpy
AvastWin32:Crypt-QBK [Trj]
TencentMalware.Win32.Gencirc.11d59aa5
Ad-AwareGen:Heur.Mint.SP.Urelas.1
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
ComodoTrojWare.Win32.Wecod.AF@55img7
BaiduWin32.Trojan.Urelas.d
ZillyaTrojan.Cardspy.Win32.74
TrendMicroTROJ_URELAS_GI080278.UVPM
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dc
SophosMal/Generic-S
IkarusTrojan.Win32.Beaugrit
GDataWin32.Trojan.PSE.1CJPTFZ
JiangminTrojan.Ekstak.budc
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan/Generic.ASMalwS.CFD10F
GridinsoftRansom.Win32.Zbot.sa
ArcabitTrojan.Mint.SP.Urelas.1
ViRobotTrojan.Win32.Z.Wecod.228484.A
MicrosoftTrojan:Win32/Urelas.AA
SentinelOneStatic AI – Malicious PE
AhnLab-V3Backdoor/Win32.Plite.R84435
Acronissuspicious
VBA32Trojan.Wecod
MalwarebytesMalware.AI.768115141
APEXMalicious
YandexTrojanSpy.CardSpy!53DhpyjygcU
MAXmalware (ai score=85)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Wecod.ALL!tr
WebrootW32.Trojan.Gen
AVGWin32:Crypt-QBK [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Ekstak.nvxw?

Trojan.Win32.Ekstak.nvxw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment