Trojan

Trojan.EkstakPMF.S3518523 removal guide

Malware Removal

The Trojan.EkstakPMF.S3518523 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.EkstakPMF.S3518523 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.EkstakPMF.S3518523?


File Info:

crc32: 0F111780
md5: 9ec3b0743a69510f79dc6067efd2b7ff
name: 9EC3B0743A69510F79DC6067EFD2B7FF.mlw
sha1: 8bc6bcbf14290d7e94bb1b854626a59c6e55dadd
sha256: 1e5500ea75f8cb21fbdc54c5bd896a837a8436bb81bb2c23ec9ab79b893a691e
sha512: 83e8c4a53c1716ac42ac9fdc34460dd89d09e9c243d3d7381001917b657fcab9afb5ada048d42cbf2d662b61726d902ccc0d233518056a328b95c2751e2cbd7e
ssdeep: 24576:TFEVC8dPjSrNHlmhWLGEGegvBGHZulpPVQZUxZGoEmzogo/pRX4y:5EN2hlmJIMlRVQZUxZGoEdb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: BPRepair.exe
FileVersion: 3.2.1117.61
Comments: Framework 3.48 Setup
ProductName: Framework 3.48 Setup
ProductVersion: 3.2.1117.61
FileDescription: Framework 3.48 Setup
OriginalFilename: BPRepair.exe
Translation: 0x0409 0x04b0

Trojan.EkstakPMF.S3518523 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0053fe731 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3673
CynetMalicious (score: 100)
CAT-QuickHealTrojan.EkstakPMF.S3518523
ALYacApplication.Bundler.BFK
CylanceUnsafe
ZillyaTrojan.Ekstak.Win32.10164
AlibabaTrojan:Win32/Selfdel.6b81ef0e
K7GWTrojan ( 0053fe731 )
Cybereasonmalicious.43a695
CyrenW32/InstallCube.P.gen!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GKQH
APEXMalicious
AvastWin32:ICLoader-X [Adw]
KasperskyUDS:Trojan.Win32.Ekstak.a
BitDefenderApplication.Bundler.BFK
NANO-AntivirusTrojan.Win32.Ekstak.fhndip
MicroWorld-eScanApplication.Bundler.BFK
TencentMalware.Win32.Gencirc.10cc4830
Ad-AwareApplication.Bundler.BFK
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GS@84429a
BitDefenderThetaGen:NN.ZexaF.34266.xw0@aWkFkVci
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
FireEyeGeneric.mg.9ec3b0743a69510f
EmsisoftApplication.Bundler.BFK (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.rkl
AviraTR/ICLoader.Gen8
Antiy-AVLTrojan/Generic.ASBOL.C526
MicrosoftTrojan:Win32/Selfdel.B
GDataApplication.Bundler.BFK
AhnLab-V3PUP/Win32.ICLoader.R249363
Acronissuspicious
McAfeeGenericRXGJ-ZI!9EC3B0743A69
MAXmalware (ai score=99)
VBA32BScope.Trojan.Fuerboos
MalwarebytesAdware.ICLoader.Generic
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!r2l46OI3Gi4
IkarusPUA.ICLoader
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:ICLoader-X [Adw]
Paloaltogeneric.ml

How to remove Trojan.EkstakPMF.S3518523?

Trojan.EkstakPMF.S3518523 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment