Trojan

Should I remove “Trojan.Win32.Ekstak.axjoy”?

Malware Removal

The Trojan.Win32.Ekstak.axjoy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.axjoy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Ekstak.axjoy?


File Info:

name: 781DF7827EF2DC08F843.mlw
path: /opt/CAPEv2/storage/binaries/54350f03359317b4e045acbbd1c07cd00e5aaa4eb0deed7554dd387711441856
crc32: A4443027
md5: 781df7827ef2dc08f843129364490ae4
sha1: 9fe77e95dc2a982f70d265c6f28a8d2d81380044
sha256: 54350f03359317b4e045acbbd1c07cd00e5aaa4eb0deed7554dd387711441856
sha512: 15bc6edc3434dada265de29af4e8afda484a442f6148ff178e4a6f6a2c92aefb95bf85b727655c42615383a7afb187b4e3fb478a57664c386c5e6dc25a0e8a6b
ssdeep: 196608:g+w23xx3tcebQtT/Ibrg2tIH6ttcpWPULVr2M2:g+wKuUIT/IbbtIattrwrA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD663306ABF45E72C19481F04A2FD048F539ACF53D31584A33EE9EDED72B64A0949BE1
sha3_384: 37e52ee391f40ed15eb001e9ca05c6424786b7bca41d6555c114e0ab883ef06a2978ecbe0c17125cb142f37c898b6b09
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2024-05-04 09:53:58

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: imedia Setup
FileVersion:
LegalCopyright:
ProductName: imedia
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.axjoy also known as:

BkavW32.AIDetectMalware
AVGOther:Malware-gen [Trj]
Elasticmalicious (high confidence)
Cylanceunsafe
SangforTrojan.Win32.Agent.V3cb
K7GWTrojan ( 005722f11 )
K7AntiVirusTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 99)
APEXMalicious
AvastOther:Malware-gen [Trj]
KasperskyTrojan.Win32.Ekstak.axjoy
TencentWin32.Trojan.Ekstak.Uwhl
F-SecureHeuristic.HEUR/AGEN.1373347
Trapminemalicious.high.ml.score
SophosMal/Generic-S
Paloaltogeneric.ml
AviraHEUR/AGEN.1373347
KingsoftWin32.Trojan.Ekstak.a
MicrosoftTrojan:Win32/Sonbokli.A!cl
ZoneAlarmTrojan.Win32.Ekstak.axjoy
GDataWin32.Backdoor.Bodelph.SDMCPI
VaristW32/ABRisk.JYOT-9195
AhnLab-V3Trojan/Win.Malware-gen.R647197
TrendMicro-HouseCallTROJ_GEN.R002H0CE424
IkarusTrojan.Win32.Crypt
FortinetW32/Agent.SLC!tr
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Ekstak.asQbz

How to remove Trojan.Win32.Ekstak.axjoy?

Trojan.Win32.Ekstak.axjoy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment