Trojan

Trojan.Win32.Ekstak.dymq removal guide

Malware Removal

The Trojan.Win32.Ekstak.dymq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.dymq virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Ekstak.dymq?


File Info:

crc32: B082A7E9
md5: b1edf5b080983aaf9743ccd0960672cc
name: B1EDF5B080983AAF9743CCD0960672CC.mlw
sha1: 029f5190c6cefb10d18e3e1fc4c7ec92c806e89b
sha256: 21850eecbd0b9629072a1cc94c0d4b06ede27ce0814530e6f606735afe528952
sha512: 0232d62b64e5398c63c0c4c3951e33c2562faa89756baa62e143dc35156f91b977087271a505f2c156f6373e0062f78754540e74a3c32c98fe3f33ba52c7815e
ssdeep: 49152:LDU/vkc0mruqvo0EC8WfATyvcO4z1Pq3eAQ+:v+vkc0m9nAWvcOuPq3eAF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Ekstak.dymq also known as:

K7AntiVirusTrojan ( 00528e7f1 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3265
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Ekstak.A02
ALYacTrojan.Mint.Zamg.J
CylanceUnsafe
ZillyaTrojan.Ekstak.Win32.5890
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 00528e7f1 )
Cybereasonmalicious.080983
CyrenW32/Trojan.FSL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GEMJ
APEXMalicious
AvastWin32:AdwareSig [Adw]
ClamAVWin.Dropper.Icloader-6553203-0
KasperskyTrojan.Win32.Ekstak.dymq
BitDefenderTrojan.Mint.Zamg.J
NANO-AntivirusTrojan.Win32.InstallCube.eyxpak
MicroWorld-eScanTrojan.Mint.Zamg.J
TencentMalware.Win32.Gencirc.10b3e603
Ad-AwareTrojan.Mint.Zamg.J
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GS@84429a
VIPRETrojan.Win32.Generic!BT
TrendMicroPUA.Win32.ICLOADER.SM
McAfee-GW-EditionGenericRXEI-IH!B1EDF5B08098
FireEyeGeneric.mg.b1edf5b080983aaf
EmsisoftApplication.InstallMon (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.bpef
AviraTR/Crypt.ZPACK.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Ekstak
MicrosoftPUADlManager:Win32/InstallCube
ArcabitTrojan.Mint.Zamg.J
GDataWin32.Application.ICLoader.F
AhnLab-V3PUP/Win32.ICLoader.R224062
Acronissuspicious
McAfeeGenericRXEI-IH!B1EDF5B08098
MAXmalware (ai score=97)
VBA32BScope.Trojan.Ekstak
MalwarebytesMalware.AI.950020533
PandaTrj/Genetic.gen
TrendMicro-HouseCallPUA.Win32.ICLOADER.SM
RisingTrojan.Kryptik!1.B07D (CLASSIC)
YandexTrojan.GenAsa!QZ0uzQAZCB8
IkarusPUA.FileTour
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]
Paloaltogeneric.ml

How to remove Trojan.Win32.Ekstak.dymq?

Trojan.Win32.Ekstak.dymq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment