Trojan

Trojan.Win32.Ekstak.aofmv removal

Malware Removal

The Trojan.Win32.Ekstak.aofmv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.aofmv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Ekstak.aofmv?


File Info:

name: D8C34DFB280F029F0A00.mlw
path: /opt/CAPEv2/storage/binaries/ecf7e82e0a9d282345b9fa77f545e9b8cb3f33191f38fece1744b20b5d3944db
crc32: F8DAE869
md5: d8c34dfb280f029f0a00305424eb849a
sha1: 56986fba46f677c2fb927da298a1bd9b44c2ced2
sha256: ecf7e82e0a9d282345b9fa77f545e9b8cb3f33191f38fece1744b20b5d3944db
sha512: 4b56061a55ae55870d9a73f7e2e3e1465621335c419a3fbb3cc48bf35c7c9cdb8fd1e6915de51954cd6e4b4781370d361355fc7f7d5bf0f90af8a54f1db2e053
ssdeep: 98304:9i85g3WAATF5WTf6YnISmczFVPYP0WCctM/B/k2Asxxc4zWKYpD:kbATF5cBIwFVPY8WCctM/B/HqOWKK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F206331171EA3478E0501FF03E51013D4129FE2C98F93A6C7EBE16376766E5A4AACB1B
sha3_384: 962144635a821995abe3c875367d0d03b01f066a91a398d1d9a42c58f30f749b26f4a7ea7b1b2f261b00763c805dbb6f
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 2023-08-13 20:57:51

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: Inno Setup Setup
FileVersion:
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.aofmv also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
McAfeeArtemis!D8C34DFB280F
MalwarebytesAgent.Trojan.Dropper.DDS
SangforDropper.Win32.Ekstak.V6rs
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Ekstak.a20d3439
K7GWTrojan ( 005722fe1 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/Ekstak.HK.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.aofmv
AvastOther:Malware-gen [Trj]
F-SecureTrojan.TR/Drop.Agent.tokay
McAfee-GW-EditionBehavesLike.Win32.ObfuscatedPoly.wc
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Ekstak.chws
AviraTR/Drop.Agent.tokay
ZoneAlarmTrojan.Win32.Ekstak.aofmv
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Malware-gen.R582708
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CHI23
MaxSecureTrojan.Malware.215889104.susgen
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Ekstak.aofmv?

Trojan.Win32.Ekstak.aofmv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment