Trojan

Trojan.Win32.Ekstak.ahuvf removal

Malware Removal

The Trojan.Win32.Ekstak.ahuvf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.ahuvf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs

How to determine Trojan.Win32.Ekstak.ahuvf?


File Info:

crc32: 42FDE916
md5: c6ff24780ae5668145c49bd2d96ec02f
name: C6FF24780AE5668145C49BD2D96EC02F.mlw
sha1: 02467b685bdddcebaf8abbdd1dcae291405281ec
sha256: 9da06dde7f56fd3988599789f932819c4794b72978149e48391590fedac365d7
sha512: edd7e722282929f63b4617ee84c098c5a7a792cd72a0aa8756dcb1084109d241dea4795d24116cd67d10516601497679ee3fe488771c6992113000ea5f7293bb
ssdeep: 196608:E2DpmN6PXjAO0TNz43iSXup+BSiu/tBz3xwMv4ARpZlJXf9Y11Bj:EimN6fLQWzXo+BSiu/tBzXnRHKXBj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 1.0.0.0
CompanyName: CMS Software
Comments: This installation was built with Inno Setup.
ProductName: IdeoMONTAGE
ProductVersion: 9.25
FileDescription: x412x438x434x435x43ex41cx41ex41dx422x410x416
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.ahuvf also known as:

K7AntiVirusTrojan ( 005722fe1 )
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.1673
CynetMalicious (score: 99)
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Ekstak.423ec03e
K7GWTrojan ( 005722fe1 )
CyrenW32/Agent.CFH.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
KasperskyTrojan.Win32.Ekstak.ahuvf
TencentWin32.Trojan-dropper.Agent.Tbit
SophosMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
JiangminTrojan.Ekstak.bocw
AviraHEUR/AGEN.1140309
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3PUP/Win32.DownloadAssistant.R361380
McAfeeArtemis!C6FF24780AE5
MalwarebytesAdware.DownloadAssistant
IkarusTrojan-Dropper.Win32.Agent
FortinetPossibleThreat.MU
AVGWin32:AdwareX-gen [Adw]

How to remove Trojan.Win32.Ekstak.ahuvf?

Trojan.Win32.Ekstak.ahuvf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment