Trojan

Trojan.Win32.Ekstak.auioi (file analysis)

Malware Removal

The Trojan.Win32.Ekstak.auioi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.auioi virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Ekstak.auioi?


File Info:

name: 9AD6BA057C97E36263A1.mlw
path: /opt/CAPEv2/storage/binaries/2e7cfe306970ba48c28d9aff2d8146282e6b20ad70c40213be2661d7514d7e1d
crc32: 03936D94
md5: 9ad6ba057c97e36263a1e2a6471615e8
sha1: 93775a3eefcb3aca771dd786003ce877b012f9dd
sha256: 2e7cfe306970ba48c28d9aff2d8146282e6b20ad70c40213be2661d7514d7e1d
sha512: 22f20f4949d9079ce74c3f12ad9cc9b308e0d317f801160fb845e04e8979d89a07fe1de9ffb196edaaac9edb5963d2ee9981bdb21cd80796b96398b0c9ffa5ed
ssdeep: 98304:SoGeDkWd85m8O2c+BteAf+v2ROFDnbV55Mk6E7o89TowaKgZD24dm8:hGeDt8m8CwcEZMr55VkgEz24dD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0563363F7864EF3C395ED35B984DA9A4D4A7E1E1272E8486D7B0FCB8B313A08156131
sha3_384: 0f0a184cddf24f392c3b600143a90a3c688061c45c9c70076c855add2fbed9a42bcbb09c9b7eb03fe5bdc173f2dfc535
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-12-27 13:31:49

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: ZPointLIB Setup
FileVersion:
LegalCopyright:
ProductName: ZPointLIB
ProductVersion: 1.2.2.7
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.auioi also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
CynetMalicious (score: 99)
SkyhighBehavesLike.Win32.PUPInstaller.vc
McAfeeArtemis!9AD6BA057C97
MalwarebytesGeneric.Malware/Suspicious
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
ClamAVWin.Malware.Generic-10017587-0
KasperskyTrojan.Win32.Ekstak.auioi
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan.Ekstak.Vwhl
F-SecureTrojan.TR/Drop.Agent.shrvi
DrWebTrojan.Siggen22.55029
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
AviraTR/Drop.Agent.shrvi
Kingsoftmalware.kb.a.841
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Ekstak.auioi
GDataWin32.Trojan.Agent.J4PFNB
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0DLR23
FortinetW32/Agent.SLC!tr
AVGWin32:AdwareX-gen [Adw]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Ekstak.auioi?

Trojan.Win32.Ekstak.auioi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment