Trojan

What is “Trojan.Win32.Ekstak.akbya”?

Malware Removal

The Trojan.Win32.Ekstak.akbya is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.akbya virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Win32.Ekstak.akbya?


File Info:

name: 93A6A12DCE62A598340F.mlw
path: /opt/CAPEv2/storage/binaries/4f54af4418d1cd9c575378f084a62a08a5dc83c765b375ed709daeec006b9a5e
crc32: 487C8198
md5: 93a6a12dce62a598340fd53bfcd93cd2
sha1: 6e6a078b7ab81fe4a458e249cc3256850f75e30b
sha256: 4f54af4418d1cd9c575378f084a62a08a5dc83c765b375ed709daeec006b9a5e
sha512: 11ebb3057fb3c5e4c30982f07603c5902a469023d599bbba405c40bd3f0dab4ba238fef0771435d56707d9ff6f81cd60e8c2bd7679cab08f5ac01cbd3d435edf
ssdeep: 98304:PX4qEmNTtpJSeTeVCaNv5ENyRTnBLY2P2yazx14:vzTfXTeDNhfTr+ya0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154060227B298753EC4AA37354673A05058FBB66DF423BE1637E4C48CCF660C11E3AA65
sha3_384: 8aadc48ace5ebc746e3d972de67e1c51947ebe9a7dab0683c62555306eb4ee3dcbf680af53942cd7e9c75a39ed4bda8d
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2019-04-27 08:22:11

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Eaque Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Eaque
ProductVersion: 4.14.12.2
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.akbya also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36916679
FireEyeTrojan.GenericKD.36916679
ALYacTrojan.GenericKD.36916679
CylanceUnsafe
SangforTrojan.Win32.Ekstak.akbya
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.3caf5294
K7GWTrojan ( 005722f11 )
CyrenW32/Agent.COB.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
AvastNSIS:Downloader-ADB [Trj]
KasperskyTrojan.Win32.Ekstak.akbya
BitDefenderTrojan.GenericKD.36916679
TencentWin32.Trojan.Ekstak.Htlu
SophosMal/Generic-S + Troj/Agent-BGXK
DrWebTrojan.Zadved.1686
TrendMicroTROJ_GEN.R002C0RB422
McAfee-GW-EditionBehavesLike.Win32.CSDImonetize.wc
EmsisoftTrojan.GenericKD.36916679 (B)
AviraHEUR/AGEN.1142804
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Downloader.Win32.Adload.gen
GDataWin32.Backdoor.Bodelph.PGDUA4
CynetMalicious (score: 99)
McAfeeArtemis!93A6A12DCE62
MAXmalware (ai score=88)
VBA32Trojan.Zadved
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002C0RB422
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.8964!tr
AVGNSIS:Downloader-ADB [Trj]
PandaTrj/CI.A

How to remove Trojan.Win32.Ekstak.akbya?

Trojan.Win32.Ekstak.akbya removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment