Trojan

Trojan.Win32.Ekstak.aouqr removal tips

Malware Removal

The Trojan.Win32.Ekstak.aouqr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.aouqr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Ekstak.aouqr?


File Info:

name: D050B46FD0D0F7443D51.mlw
path: /opt/CAPEv2/storage/binaries/aaa6b0be8b5010f3c0f58d027c1407c70b477c8ca626e4011cec5eef76ac2b29
crc32: EDB94147
md5: d050b46fd0d0f7443d510d92056369a7
sha1: fe1cbf3d599f7c523f452a9aaf4447a8b41ac923
sha256: aaa6b0be8b5010f3c0f58d027c1407c70b477c8ca626e4011cec5eef76ac2b29
sha512: 32fb80776b8b863e3eb6e98e0a106369e9790275c3e5ec92ec700faf07b65a3552e148ab9d2023d1c9d295b2843b7d3792855cfecb875d6dfc7edab4a3354119
ssdeep: 98304:+WaRT9aHUnMehCblZKEDAqr/DzOwIWiydiA3dc4r1X4jYAPVUVN4Ql:uRT9JnMSwkED4wIEdiA3dc4r1X4jdDW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126363353BE21C93CE01543FCAD51C11990FAFD9AAC313B4AB9E87D1F3134AA7A805279
sha3_384: 29df6f4dd92876a5dcd5b7c0c79f211351cb84382edd95d6332ea3fa99ba4b952425fe567abe60e1c119f081a2bc3375
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-09-28 17:27:27

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: DHRoller Setup
FileVersion:
LegalCopyright:
ProductName: DHRoller
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.aouqr also known as:

BkavW32.AIDetectMalware
DrWebTrojan.Zadved.1793
McAfeeArtemis!D050B46FD0D0
MalwarebytesAdware.DownloadAssistant
CyrenW32/ABRisk.XQBH-0133
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.aouqr
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan.Ekstak.Rimw
F-SecureHeuristic.HEUR/AGEN.1332256
McAfee-GW-EditionBehavesLike.Win32.ObfuscatedPoly.tc
Trapminesuspicious.low.ml.score
AviraHEUR/AGEN.1332256
ZoneAlarmTrojan.Win32.Ekstak.aouqr
MicrosoftTrojan:Win32/ICLoader.JLK!MTB
TrendMicro-HouseCallTROJ_GEN.R002H0CIS23
IkarusTrojan-Dropper.Win32.Agent
FortinetRiskware/Agent
AVGWin32:AdwareX-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.Win32.Ekstak.aouqr?

Trojan.Win32.Ekstak.aouqr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment