Trojan

Trojan.Agent.EKSK malicious file

Malware Removal

The Trojan.Agent.EKSK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EKSK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

wtfismyip.com
redirector.gvt1.com

How to determine Trojan.Agent.EKSK?


File Info:

crc32: F00042E0
md5: 6a3302cbcfd0fd51a287797c33c3c573
name: flygame.png
sha1: d6e029f9c23d855829da762088f7f771a72ac1a8
sha256: b75cbde6a1d1cb04811ba1d48c5007077fba0c3cfa1d6167723938a330b4eb1e
sha512: 2384741e6c6151392903efea132d037a5b356d8aee9e006497b1c9be764cee21c3911022a33f7a3c731f4f8d319557077c4725646e143d0f16264e223d74953c
ssdeep: 12288:ZLH7FWwJuaw7uc+sSGBZAbRC3t+EMZnWrXxC6Wy8H:U6c+sSGBZAbRYvMixMH
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: CMap
FileVersion: 1.0.0.0
CompanyName: Ricky Bull
Comments: clsASMpic is a simple class that makes possible
ProductName: Character Map
ProductVersion: 1.0.0.0
OriginalFilename: CMap.exe

Trojan.Agent.EKSK also known as:

MicroWorld-eScanTrojan.Agent.EKSK
FireEyeGeneric.mg.6a3302cbcfd0fd51
McAfeeGenericRXAA-AA!6A3302CBCFD0
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderTrojan.Agent.EKSK
Cybereasonmalicious.9c23d8
BitDefenderThetaGen:NN.ZevbaF.34084.Cm1@aKtvLsgm
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EKFY
GDataTrojan.Agent.EKSK
KasperskyTrojan.Win32.Mansabo.edn
APEXMalicious
RisingTrojan.Trickbot!8.E313 (C64:YzY0OmI0hATdhqtF)
Endgamemalicious (high confidence)
EmsisoftTrojan.Agent.EKSK (B)
F-SecureTrojan.TR/AD.TrickBot.byib
Invinceaheuristic
Trapminemalicious.moderate.ml.score
SentinelOneDFI – Malicious PE
WebrootW32.Trojan.Trickbot
AviraTR/AD.TrickBot.byib
MAXmalware (ai score=83)
ArcabitTrojan.Agent.EKSK
AhnLab-V3Trojan/Win32.Agent.C3974862
ZoneAlarmTrojan.Win32.Mansabo.edn
Acronissuspicious
Ad-AwareTrojan.Agent.EKSK
PandaTrj/TrickBot.A
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.E31F.Malware.Gen

How to remove Trojan.Agent.EKSK?

Trojan.Agent.EKSK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment