Trojan

Trojan.Win32.Ekstak.aoxcr removal

Malware Removal

The Trojan.Win32.Ekstak.aoxcr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.aoxcr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates known PcClient mutex and/or file changes.
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Ekstak.aoxcr?


File Info:

name: EF1B5D75EE05419F0DC4.mlw
path: /opt/CAPEv2/storage/binaries/64f3a59f616e2c288988ea08984f109ff1834f4a81c0153bec97095b04213b08
crc32: C2303C3B
md5: ef1b5d75ee05419f0dc4261fff218b0b
sha1: 07b14334b102d9fb528d0cd44af699bfdb95c480
sha256: 64f3a59f616e2c288988ea08984f109ff1834f4a81c0153bec97095b04213b08
sha512: dc3c58e11fc1051d114464ef9d53c2a9208668cec595ab9fe49992ee0853aeb742dc78c163796f8682f2f3ce2b2d93f983ac9f1fad26199acb0c76d618107f4a
ssdeep: 196608:1OpNA9H57t/64yMGRXfMa6TWJ30jX7f1VMrc06/NedFK:ssPsltf36Tzj1Vo61edg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A9633B7A2612932D8B7EB774F53033280982B7516381A45E2CE4BEC727928B0D75FD5
sha3_384: b82d92628ae9f12252f2da2b97ee31f230b6efa2c371869b08385200b8f97be34ca9e3f57475469aadd7a5019d7057ff
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-10-05 00:38:52

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: chrtools Frontend Setup
FileVersion:
LegalCopyright:
ProductName: chrtools Frontend
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.aoxcr also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MalwarebytesAdware.DownloadAssistant
CrowdStrikewin/malicious_confidence_90% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.aoxcr
AvastOther:Malware-gen [Trj]
McAfee-GW-EditionBehavesLike.Win32.BadFile.rc
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
ZoneAlarmTrojan.Win32.Ekstak.aoxcr
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!EF1B5D75EE05
Cylanceunsafe
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Ekstak.aoxcr?

Trojan.Win32.Ekstak.aoxcr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment