Trojan

About “Trojan.Win32.Ekstak.ajtez” infection

Malware Removal

The Trojan.Win32.Ekstak.ajtez is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.ajtez virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Win32.Ekstak.ajtez?


File Info:

name: 506100124B03F4EE6481.mlw
path: /opt/CAPEv2/storage/binaries/946b293250572caa6997dd3ffb42b5ba82261603d37de425da2845e15f1b1b65
crc32: 79E04F38
md5: 506100124b03f4ee6481e2dfe69d3870
sha1: f1161028b30d2b1a297e72a64032090173c1224b
sha256: 946b293250572caa6997dd3ffb42b5ba82261603d37de425da2845e15f1b1b65
sha512: 20df611e762087fe86a9b00e8116098dc9cde87904acc468bfabb12eb4ccf9426c8f093f22dc59eae64fdbafe9cdee8097a71ce93fb3deaa528e755c122bec1f
ssdeep: 98304:8SigIhLpLPtjHjdIq+Cy7C94XzZZ45ktA3Re/gKKCDnWDkP1Q:jIhL5PcX7e49Z0E6RAgHCDcktQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19916023FB268653ED4AE0B3245B39360597BBB64B81A8C1F57F0090CCF665711E3BA16
sha3_384: d231e4aca9d9aa0064de8b1a675047e10530f7b370455c4788e5e4a018fbc2ee73fbe949e5c12e3a52a088f38f204d1e
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-11-15 09:48:30

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Qui Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Qui
ProductVersion: 6.15.4.13
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.ajtez also known as:

LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader38.30112
MicroWorld-eScanTrojan.GenericKD.36691784
FireEyeTrojan.GenericKD.36691784
ALYacTrojan.GenericKD.36691784
CylanceUnsafe
SangforTrojan.Win32.Ekstak.ajtez
K7AntiVirusTrojan ( 005615151 )
AlibabaTrojan:Win32/Ekstak.41d2f9ad
K7GWTrojan ( 005615151 )
CyrenW32/Agent.CNP.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
AvastWin32:AdwareX-gen [Adw]
ClamAVWin.Adware.Dealalpha-9835537-0
KasperskyTrojan.Win32.Ekstak.ajtez
BitDefenderTrojan.GenericKD.36691784
NANO-AntivirusVirus.Win32.Gen.ccmw
Ad-AwareTrojan.GenericKD.36691784
EmsisoftTrojan.GenericKD.36691784 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0RB922
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
SophosMal/Generic-R
GDataWin32.Trojan.BSE.W4BXSV
AviraHEUR/AGEN.1237241
GridinsoftRansom.Win32.Wacatac.sa
ZoneAlarmTrojan.Win32.Ekstak.ajtez
MicrosoftTrojan:Win32/Mamson.A!ml
CynetMalicious (score: 99)
McAfeeArtemis!506100124B03
MAXmalware (ai score=85)
VBA32Trojan.Ekstak
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002C0RB922
RisingTrojan.Kryptik!1.AA23 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/Ekstak
AVGWin32:AdwareX-gen [Adw]
PandaTrj/CI.A

How to remove Trojan.Win32.Ekstak.ajtez?

Trojan.Win32.Ekstak.ajtez removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment