Trojan

Should I remove “Trojan.Win32.Ekstak.aoxgw”?

Malware Removal

The Trojan.Win32.Ekstak.aoxgw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.aoxgw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates known PcClient mutex and/or file changes.
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Ekstak.aoxgw?


File Info:

name: 2410BFFD94F1353DD74C.mlw
path: /opt/CAPEv2/storage/binaries/3af43cafaacc4c56b79a4f26a840f211422a46839852acaca68007696921cab8
crc32: AF360F86
md5: 2410bffd94f1353dd74c7e4fb39f1708
sha1: 05740c5ed976196765c93dfe78bcfdbac7b66f5e
sha256: 3af43cafaacc4c56b79a4f26a840f211422a46839852acaca68007696921cab8
sha512: 9ad9d28c5bfbc4ccc4134c5f21f1a81d714eaf6f9b073f22e35ce34b27f146fe90f04ea55599fbb1812b56330f7c748edbd5b2bc1aa96a81d00a7478ed604a2a
ssdeep: 196608:lwQdaiND08H8bZQ5yUCBVFvjwM13kNcronK+KEnkqGGvTK:cKpuK5C/wM3wK+KEkjGO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11196336728568433E048EA7C19BCC9F495EB75821C6AA363B5FC064B9B1728BFC137D1
sha3_384: 4c5874dd2e3a231f50916c90c42cfa01ec2e490b1b6bcc5fb0f308f8700dae48c9e5d97934cb365b84e7bfa901755072
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-10-05 15:31:20

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: cjrtools Frontend Setup
FileVersion:
LegalCopyright:
ProductName: cjrtools Frontend
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.aoxgw also known as:

BkavW32.AIDetectMalware
SkyhighArtemis
MalwarebytesAdware.DownloadAssistant
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.aoxgw
AvastOther:Malware-gen [Trj]
SophosMal/Generic-S
ZoneAlarmTrojan.Win32.Ekstak.aoxgw
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!2410BFFD94F1
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Ekstak.aoxgw?

Trojan.Win32.Ekstak.aoxgw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment