Trojan

Trojan.Win32.Ekstak.aogcn removal tips

Malware Removal

The Trojan.Win32.Ekstak.aogcn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.aogcn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Ekstak.aogcn?


File Info:

name: 21F39F7C1F7783FFC8DE.mlw
path: /opt/CAPEv2/storage/binaries/205e086fae4a154939a5388ccac5c7ec0fb6c6b646df7fcdd9a8d6080690d831
crc32: BDCF6B30
md5: 21f39f7c1f7783ffc8decf46c1d55d29
sha1: 434fd0b25f96bdeee468702dc409f2fdfca7da03
sha256: 205e086fae4a154939a5388ccac5c7ec0fb6c6b646df7fcdd9a8d6080690d831
sha512: 123e529742643666b45ce5e0a40f7c0f8e104dc2a0115397895247b26a2207c86f22cc18f5e87de70a2c2d43159875439f3d58e6cbbad1406f65b46a0fc1b04f
ssdeep: 98304:aiLCOXNhL6nQo6iVJISNyxa3G5R+7APjxJ4MEeNsvYp0:PLCOX7OnH6GISAx4GnEAPtmCsvx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB063397FCA0CBA5E1934274BFB6E21109323C2E3F3819691BC850DC9B5E681F55E726
sha3_384: 65aee0928e0873732913fe1ce4ecdf3f8ebe84d460abf32768c14a9900ffc15ac911e8a274fba18214ff197c4b6a0ff7
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 2023-08-15 20:02:47

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: Inno Setup Setup
FileVersion:
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.aogcn also known as:

BkavW32.AIDetectMalware
McAfeeArtemis!21F39F7C1F77
CyrenW32/Ekstak.HK.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Ekstak.aogcn
AvastOther:Malware-gen [Trj]
F-SecureTrojan.TR/AD.Nekark.vxovp
McAfee-GW-EditionBehavesLike.Win32.ObfuscatedPoly.wc
AviraTR/AD.Nekark.vxovp
ZoneAlarmTrojan.Win32.Ekstak.aogcn
MicrosoftTrojan:Win32/Wacatac.B!ml
MalwarebytesAgent.Trojan.Dropper.DDS
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Ekstak.aogcn?

Trojan.Win32.Ekstak.aogcn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment