Trojan

Trojan.Win32.Ekstak.axebu removal

Malware Removal

The Trojan.Win32.Ekstak.axebu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.axebu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Ekstak.axebu?


File Info:

name: BAE22833217B951C1CFD.mlw
path: /opt/CAPEv2/storage/binaries/9db2b7ef5fefb207f061ba2ed25c26d56db3bd4a09b7fe4524fea232c761fc07
crc32: 3F80EE98
md5: bae22833217b951c1cfd0e29001ba4da
sha1: 2516728d3a49393e818fba4762a0d5db03a110f2
sha256: 9db2b7ef5fefb207f061ba2ed25c26d56db3bd4a09b7fe4524fea232c761fc07
sha512: 43b4d6c7c50c06bec3e897b9a565b30b17d78b530e6cc953af7677c1b804895ee813116c591090493b7ab6ad3a0cf58d1d3086fb941cf5cba00d4a760caa891b
ssdeep: 196608:txGjN1keyE/8wj+/nAiFdHbM2qsqCq+7hHu:tsN1keP/0AiDH3T7hHu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A763343FEBA007ECA79D8F10E05AB10C6139AADDA346C4252DCCD8A4750E98FD5DF4A
sha3_384: 09a8edd80d31b295e59eb79921381312123a786d5e6394f6a8e8d2e4d6101b4cab9ae8a02ca495b07131d68de76bb5cc
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 2024-04-15 00:00:39

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: Audacity Sound Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan.Win32.Ekstak.axebu also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Munp.1
FireEyeGen:Heur.Munp.1
SkyhighBehavesLike.Win32.ObfuscatedPoly.wc
MalwarebytesBackdoor.TVRat.Dropper
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002H0CDE24
KasperskyTrojan.Win32.Ekstak.axebu
BitDefenderGen:Heur.Munp.1
TencentWin32.Trojan.Ekstak.Snkl
EmsisoftGen:Heur.Munp.1 (B)
F-SecureHeuristic.HEUR/AGEN.1372994
VIPREGen:Heur.Munp.1
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
VaristW32/Agent.RSMX-8923
AviraHEUR/AGEN.1372994
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Munp.1
ZoneAlarmTrojan.Win32.Ekstak.axebu
GDataGen:Heur.Munp.1
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R645160
McAfeeArtemis!BAE22833217B
GoogleDetected
MAXmalware (ai score=81)
Cylanceunsafe
PandaTrj/Chgt.AD
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.240296011.susgen
FortinetW32/Agent.SLC!tr
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Ekstak.axebu

How to remove Trojan.Win32.Ekstak.axebu?

Trojan.Win32.Ekstak.axebu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment