Trojan

About “Trojan.Win32.Ekstak.ajzcw” infection

Malware Removal

The Trojan.Win32.Ekstak.ajzcw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.ajzcw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Win32.Ekstak.ajzcw?


File Info:

name: 0AD4F45807A771C2158A.mlw
path: /opt/CAPEv2/storage/binaries/fd03ead7ade5ebb26ec8b09884b47703e7a9a008d8d5f3e2dd4125cdc7a13fc3
crc32: 74569221
md5: 0ad4f45807a771c2158a88a65b856eb6
sha1: a45f5df83112967f81efd22164dbd48745cd5630
sha256: fd03ead7ade5ebb26ec8b09884b47703e7a9a008d8d5f3e2dd4125cdc7a13fc3
sha512: 44f8edf8fe1f86b4617ed00b255ab48c25d178268d11c171e8e8ea76701658be0e050c8260f44ed685e0bc23314a6df9065cc1cee192fbbd01c2dae881ef28da
ssdeep: 98304:PX4DRvea2M69w7Id8M4Fd/bomN5KXMQ5r519Id47nyazx14:vs2G6yfEWhYt19I0ya0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3261227B298A53EC4AE27354673A41054FBB66DF817BE1637E0C48DCF660C01E3AB65
sha3_384: 75985efd16e32f198024f0f4b0ba7ee8128b1b579e8def494655a1ade492ae9f63940cec308cb82a0b65547e7e0e764f
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2019-04-27 08:22:11

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Inventore Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Inventore
ProductVersion: 1.0.19.13
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.ajzcw also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.1686
CylanceUnsafe
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Ekstak.2b02d3ea
K7GWTrojan ( 005722fe1 )
CyrenW32/Agent.CRZ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002C0RKP21
KasperskyTrojan.Win32.Ekstak.ajzcw
NANO-AntivirusTrojan.Win32.Ekstak.iusocc
AvastNSIS:Downloader-ADB [Trj]
TencentTrojan.Win32.BitCoinMiner.la
TrendMicroTROJ_GEN.R002C0RKP21
McAfee-GW-EditionBehavesLike.Win32.CSDImonetize.rc
SophosMal/Generic-S + Troj/Agent-BGXK
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73828843.susgen
AviraHEUR/AGEN.1142804
MicrosoftTrojan:Script/Phonzy.A!ml
GDataWin32.Backdoor.Bodelph.5K5EA5
CynetMalicious (score: 99)
McAfeeArtemis!0AD4F45807A7
VBA32Trojan.Ekstak
MalwarebytesAdware.DownloadAssistant
APEXMalicious
YandexTrojan.Ekstak!wPTUJxXjuJ0
IkarusPUA.Optional.Install
FortinetW32/Agent.8964!tr
AVGNSIS:Downloader-ADB [Trj]
PandaTrj/CI.A

How to remove Trojan.Win32.Ekstak.ajzcw?

Trojan.Win32.Ekstak.ajzcw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment