Trojan

Trojan.Win32.Ekstak.dmpn information

Malware Removal

The Trojan.Win32.Ekstak.dmpn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.dmpn virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key

Related domains:

ec2-52-29-33-28.eu-central-1.compute.amazonaws.com

How to determine Trojan.Win32.Ekstak.dmpn?


File Info:

crc32: DDD3D2C6
md5: 59245a8a7db87453efde4e3678e5e192
name: 59245A8A7DB87453EFDE4E3678E5E192.mlw
sha1: 56fba481df3fd03a5eaeeb0468d3dd66efc7c1b5
sha256: 1a4ac513901626b381134e18c8dc63c3257debe1be17ca3df3ab33c32e04c1ec
sha512: 6cbdf3b1934a179a376f7b447c444cce4463e073f02e81d93b73dc2eb3abed8483f7a115d0a5f192604162aeea6e0c8a04c03236a0c4b1f39b407257a857e4c4
ssdeep: 49152:yi3ch5FxGuAp/gV0chPGct4yu5eVhaAk+lR:cTjGuQ/g2KPGctxBlf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Ekstak.dmpn also known as:

K7AntiVirusTrojan ( 00528e7f1 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2662
CynetMalicious (score: 100)
CAT-QuickHealPUA.IcloaderPMF.S19636164
ALYacGen:Variant.Zusy.398343
CylanceUnsafe
ZillyaTrojan.Ekstak.Win32.14993
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Ekstak.856a894a
K7GWTrojan ( 00525a491 )
Cybereasonmalicious.a7db87
CyrenW32/S-ed1aa36b!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GCPJ
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Packed.Icloader-6952325-0
KasperskyTrojan.Win32.Ekstak.dmpn
BitDefenderGen:Variant.Zusy.398343
NANO-AntivirusRiskware.Win32.ICLoader.exlqzx
MicroWorld-eScanGen:Variant.Zusy.398343
TencentMalware.Win32.Gencirc.11491fb2
Ad-AwareGen:Variant.Zusy.398343
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GCO@7hwoq2
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPacked-VJ!59245A8A7DB8
FireEyeGeneric.mg.59245a8a7db87453
EmsisoftApplication.FileTour (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.gio
AviraTR/Crypt.XPACK.Gen2
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.244F3F8
MicrosoftSoftwareBundler:Win32/ICLoader
ArcabitTrojan.Zusy.D61407
GDataGen:Variant.Zusy.398343
AhnLab-V3PUP/Win32.ICLoader.R219807
Acronissuspicious
McAfeePacked-VJ!59245A8A7DB8
MAXmalware (ai score=88)
VBA32BScope.Trojan.InstallCube
MalwarebytesAdware.FileTour
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AFA6 (CLASSIC)
YandexTrojan.GenAsa!hawjt5MU2GE
IkarusPUA.Win32.ICLoader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Trojan.Win32.Ekstak.dmpn?

Trojan.Win32.Ekstak.dmpn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment