Trojan

Trojan.Win32.Ekstak.apnws removal tips

Malware Removal

The Trojan.Win32.Ekstak.apnws is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.apnws virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Ekstak.apnws?


File Info:

name: 9A01459D5F774B4C8F48.mlw
path: /opt/CAPEv2/storage/binaries/1810096290f49322c2a1dc2df1edd9f1572d80d1539d30ee676403e93589bdd3
crc32: 7B8BE01F
md5: 9a01459d5f774b4c8f489e885ac22e54
sha1: 4c79fd73e6b1811d1d23f72370a701d347adf572
sha256: 1810096290f49322c2a1dc2df1edd9f1572d80d1539d30ee676403e93589bdd3
sha512: ca31dc7045f136bc2d36b9dc3e18004e92a6d0615acedf8dc616d4edc8a6eca94eea9d57f0e0f334256a19f7ece61a7544f8cd0ead599cb65f2a0cf7a42b881f
ssdeep: 196608:HXXHQaLc6NzLhVzMkvuSZnSOQ7W3KC8GSN25Q0uSMfGi6zAhg3v:HnwdcL7FNQ7W8GSNkEbei6gg3v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0963380AFB2A52BD08A83B23106C62072C1D766E7F3371D335DEE1D5FE9686E424675
sha3_384: aebaf64c353ff91b9b093ac7f59c698faaa3b6f04c6a2bc16556ba3a41ef1fc62f0148cbbabe63bb7a601093ee8f40b5
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-11-03 01:52:42

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: EDrivelib Setup
FileVersion:
LegalCopyright:
ProductName: EDrivelib
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.apnws also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
McAfeeArtemis!9A01459D5F77
MalwarebytesAdware.DownloadAssistant
SangforDropper.Win32.Ekstak.Vvse
CrowdStrikewin/malicious_confidence_70% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.apnws
AlibabaTrojanDropper:Win32/Ekstak.f501d32c
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftRansom.Win32.Wacatac.sa
ZoneAlarmTrojan.Win32.Ekstak.apnws
AhnLab-V3Trojan/Win.Malware-gen.R620725
DeepInstinctMALICIOUS
Cylanceunsafe
TencentWin32.Trojan.Ekstak.Ojgl
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
AvastOther:Malware-gen [Trj]

How to remove Trojan.Win32.Ekstak.apnws?

Trojan.Win32.Ekstak.apnws removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment