Trojan

Trojan.Win32.Ekstak.aoeis removal instruction

Malware Removal

The Trojan.Win32.Ekstak.aoeis is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.aoeis virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Ekstak.aoeis?


File Info:

name: 1174BE7D35CF90CD6360.mlw
path: /opt/CAPEv2/storage/binaries/5c4c12e1a18ae6b49bc4b17efeb02cfcc37701b2900e3c2310ed07d0dfd38d07
crc32: F428EC76
md5: 1174be7d35cf90cd6360024bcbcb69a5
sha1: 016af462e63decc52e0de87070a8292a07f71ea0
sha256: 5c4c12e1a18ae6b49bc4b17efeb02cfcc37701b2900e3c2310ed07d0dfd38d07
sha512: cc1602074c956b68608c8a20aa756d8eb38a36875545d5e44fee0668557f237898dedef283b98c721b42989b0c6845f3ff9e86dd4aec9c9d54519793d3e64f0e
ssdeep: 196608:2SjbkX7v7NglAnGd/1dgUcBBDGrpK8z7oTPXtsd58:pPQfGd/16SrI8zilsQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1768633155B84D239E6C5563092E1EA352D32F75B2D33606820AB2ADF332B873933775E
sha3_384: 08aefd2329a8eedf986f531df46ab0454b24f52aadada18c0830047a5fdf7a263d22f84e86ad260d8c0f14c6db02dcb3
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-08-09 20:24:51

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Ashh Burning Studio Setup
FileVersion:
LegalCopyright:
ProductName: Ashh Burning Studio
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.aoeis also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
McAfeeArtemis!1174BE7D35CF
Cylanceunsafe
SangforDropper.Win32.Ekstak.Vcvh
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojanDropper:Win32/Ekstak.44e95a0d
K7GWTrojan ( 005722f11 )
K7AntiVirusTrojan ( 005722f11 )
CyrenW32/ABRisk.HDLB-1008
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.aoeis
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Hajl
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1332570
McAfee-GW-EditionArtemis!Trojan
JiangminTrojan.Ekstak.chwf
AviraHEUR/AGEN.1332570
ZoneAlarmTrojan.Win32.Ekstak.aoeis
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Malware-gen.C5469787
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0CH923
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Ekstak.aoeis?

Trojan.Win32.Ekstak.aoeis removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment