Trojan

How to remove “Trojan.Win32.Ekstak.awpaw”?

Malware Removal

The Trojan.Win32.Ekstak.awpaw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.awpaw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Ekstak.awpaw?


File Info:

name: 02345FB9C890C79F9034.mlw
path: /opt/CAPEv2/storage/binaries/c6f6c0acf90c936deb16107b5bf6f1a71686a9c92339cdd0d94a4ecf75c8e6c8
crc32: 8DF03F32
md5: 02345fb9c890c79f9034e12ef9668ea5
sha1: 9b940c1887ed9e3ab0a51a7601925cf65cfba2ae
sha256: c6f6c0acf90c936deb16107b5bf6f1a71686a9c92339cdd0d94a4ecf75c8e6c8
sha512: 476a8a5c3c7dbdd12d20d13a07932c9ce3e2294bbbb6fa3a1a9fd60f35bea437fbe8e5ce21833cb55ce2c1cf8169e79685fa89373f1b81b8537e434ec9c3a34f
ssdeep: 98304:IGzPh5RRqoZZsLOT2bcncNrm8Eqp8SRFWqI9ZdvLuSy2Jcsqf:PDamL2bccVm8PC6ARQYJcsO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A836330747D47A3AF1D29A7B5D86F1B04A2F3C92A97A8C4860296F3C8777C33C949B54
sha3_384: 3e78d6eb92d60776b9b52a620e315b028ec278eaab0b6cb22b86869b5addf67ca9729fde2c11c7177615bbf952790167
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2024-03-18 16:20:10

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Site Craft Studio Setup
FileVersion:
LegalCopyright:
ProductName: Site Craft Studio
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.awpaw also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
AVGOther:Malware-gen [Trj]
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
McAfeeArtemis!02345FB9C890
Cylanceunsafe
SangforTrojan.Win32.Ekstak.Vns5
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Other.fb358e98
K7GWTrojan ( 005722f11 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 99)
APEXMalicious
KasperskyTrojan.Win32.Ekstak.awpaw
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Azlw
F-SecureHeuristic.HEUR/AGEN.1373347
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
VaristW32/Ekstak.NB.gen!Eldorado
AviraHEUR/AGEN.1373347
MicrosoftTrojan:Win32/ICLoader.JLK!MTB
ZoneAlarmTrojan.Win32.Ekstak.awpaw
GDataWin32.Backdoor.Bodelph.P2R7IZ
GoogleDetected
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0CCI24
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
alibabacloudTrojan[dropper]:Win/Ekstak.awpaw

How to remove Trojan.Win32.Ekstak.awpaw?

Trojan.Win32.Ekstak.awpaw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment