Trojan

Trojan.Win32.Ekstak.aursw removal instruction

Malware Removal

The Trojan.Win32.Ekstak.aursw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.aursw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Ekstak.aursw?


File Info:

name: 262C3E2BC0638705BE2E.mlw
path: /opt/CAPEv2/storage/binaries/92df3d5eed832cc87bde645ed3ae35367416786c6ccd449f77d0a28cf897b6a7
crc32: 6D8B3D01
md5: 262c3e2bc0638705be2ea8b3d5e6d6f8
sha1: a5bcb22e0c98db9829df9d8a3812991d0156b501
sha256: 92df3d5eed832cc87bde645ed3ae35367416786c6ccd449f77d0a28cf897b6a7
sha512: b1ea8339dabdfe6b3226b3cba61ab97b03b67e2a63c65252879e278231156f86ec27704aa205678aa3db6381eda122eddb94be00fad4cd08a8cbbcd6926dbc52
ssdeep: 98304:EiArHKyyK15N93klbNb19hLdHWoSh8EwnDA6SJ5ZgRkxkJ:FArHh/JklbN7hLd+mBn0B7Zvxk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119163303E3E8143ED9A6DDB2BC2CCBA0526AFDD72E3A807A72045DA5CD76771441364B
sha3_384: 7502d8e560d2c91908a5044555a3cb4bc52f380a3b54a7e06c6be7189ef7fd626892664c8a3ff6dc23a1cf54cce87910
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 2024-01-01 21:32:48

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: RC4 encode module Setup
FileVersion:
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.aursw also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKD.71052611
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
Cylanceunsafe
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D43C2D43
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan.Win32.Ekstak.aursw
BitDefenderTrojan.GenericKD.71052611
AvastOther:Malware-gen [Trj]
EmsisoftTrojan.GenericKD.71052611 (B)
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Ekstak.aursw
GDataWin32.Trojan.Agent.8VVOKI
AhnLab-V3Trojan/Win.Generic.C5569749
McAfeeArtemis!262C3E2BC063
MAXmalware (ai score=86)
MalwarebytesBackdoor.TVRat
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0DA124
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Ekstak.aursw?

Trojan.Win32.Ekstak.aursw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment