Trojan

Trojan.Win32.Ekstak.aitrf removal

Malware Removal

The Trojan.Win32.Ekstak.aitrf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.aitrf virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs

How to determine Trojan.Win32.Ekstak.aitrf?


File Info:

crc32: FC4A1353
md5: aa15f58f23c0f44c546b1c859a153797
name: AA15F58F23C0F44C546B1C859A153797.mlw
sha1: 7cf482a91831a09652f4ce62173158d95d1cfdad
sha256: bf3923dd5671e9871728f196b04a38b4263338d322297fb5d8192cfe14dddfda
sha512: 2dae6c8d7adbb1f23d451ffef2b22d5101453ec555b729f273644b99bbff1513b5b16f00b017ee64568fbdc111dd9a3fc5af19fa89a9d15079560d3a30ff1b01
ssdeep: 49152:zCB79YX1ULN5Altbi1BsPApGTsUcWeSooedOJOKvCO8glJoBc30Fyz/fmDJWH:+R9aULNMhylUcWeS+OLaqJpbTf0Jo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: Itaque
ProductVersion: 1.2.3.2
FileDescription: Itaque Setup
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.aitrf also known as:

K7AntiVirusTrojan ( 005722f11 )
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.1685
ClamAVWin.Trojan.Generic-9839047-0
McAfeeArtemis!AA15F58F23C0
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDropper:Win32/Ekstak.b415d9ac
K7GWTrojan ( 005722f11 )
CyrenW32/DownloadAssist.AD.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
AvastNSIS:Downloader-ADB [Trj]
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Ekstak.aitrf
NANO-AntivirusTrojan.Win32.Ekstak.ipevva
TencentWin32.Trojan.Falsesign.Llqr
SophosDownload Assistant (PUA)
McAfee-GW-EditionArtemis
SentinelOneStatic AI – Malicious PE
AviraTR/Drop.Agent.lstqj
eGambitPE.Heur.InvalidSig
MicrosoftTrojan:Win32/Ymacco.AABF
GDataWin32.Backdoor.Bodelph.O8KJM6
VBA32Trojan.Ekstak
MalwarebytesAdware.DownloadAssistant
PandaTrj/CI.A
YandexTrojan.Ekstak!jiIQzFExttg
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.SLC!tr
AVGNSIS:Downloader-ADB [Trj]
Paloaltogeneric.ml

How to remove Trojan.Win32.Ekstak.aitrf?

Trojan.Win32.Ekstak.aitrf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment