Trojan

Trojan.EkstakPMF.S3744104 removal guide

Malware Removal

The Trojan.EkstakPMF.S3744104 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.EkstakPMF.S3744104 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
static.16.249.201.195.clients.your-server.de

How to determine Trojan.EkstakPMF.S3744104?


File Info:

crc32: 64F48273
md5: aca4932946202202d67726772d800dbb
name: ACA4932946202202D67726772D800DBB.mlw
sha1: b4cb6e7c1f2e00678b1b595bf1bfd8b3a9b06a2f
sha256: 212dcf772b5c4740ecd10b8307258f871330c7fed083a165b724928b50ced90d
sha512: 997aff50c1a2da5ba3f23eba016954281f5d8a56c38f656e600d4e7597f223c8e4031eb901c19a42e20cebdef7a7f3c91ac1beeb5ca2891b11b49d809632cab3
ssdeep: 49152:YRbYpV0CeNMzf1nDsPGn4J1TeMVwKFMoDC0IOQ13lu6:UkpteWoPGnfMtMAXm31
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: XRepair.exe
FileVersion: 14.0.1056.2
ProductName: NET Components 4.53 free installer
ProductVersion: 14.0.1056.2
FileDescription: NET Components 4.53 Setup
OriginalFilename: XRepair.exe
Translation: 0x0409 0x04b0

Trojan.EkstakPMF.S3744104 also known as:

K7AntiVirusTrojan ( 0053cf7a1 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3729
CynetMalicious (score: 100)
CAT-QuickHealTrojan.EkstakPMF.S3744104
ALYacGen:Variant.Zusy.405473
CylanceUnsafe
ZillyaAdware.Ekstak.Win32.43
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Katusha.3b61b1ee
K7GWTrojan ( 0053cf7a1 )
Cybereasonmalicious.946202
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GKZJ
APEXMalicious
AvastWin32:AdwareSig [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.405473
NANO-AntivirusTrojan.Win32.GenKryptik.fiapdo
MicroWorld-eScanGen:Variant.Zusy.405473
TencentMalware.Win32.Gencirc.10cc5859
Ad-AwareGen:Variant.Zusy.405473
SophosMal/Generic-S + Mal/BadCert-Gen
ComodoApplication.Win32.ICLoader.GS@84429a
F-SecureTrojan.TR/ICLoader.Gen8
BitDefenderThetaGen:NN.ZexaF.34294.Ls1@aKJ7Kgai
McAfee-GW-EditionPacked-FME!ACA493294620
FireEyeGeneric.mg.aca4932946202202
EmsisoftApplication.Generic (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.gvhyu
AviraTR/ICLoader.Gen8
Antiy-AVLTrojan/Win32.Ekstak
MicrosoftPUADlManager:Win32/InstallCube
ArcabitTrojan.Zusy.D62FE1
GDataGen:Variant.Zusy.405473
AhnLab-V3PUP/Win32.ICLoader.R237871
Acronissuspicious
McAfeePacked-FME!ACA493294620
MAXmalware (ai score=100)
VBA32BScope.Trojan.Downloader
MalwarebytesAdware.FileTour
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!4Lv5EaxRa6A
IkarusPUA.FileTour
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]
Paloaltogeneric.ml

How to remove Trojan.EkstakPMF.S3744104?

Trojan.EkstakPMF.S3744104 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment