Trojan

Trojan.Win32.Ekstak.hxea information

Malware Removal

The Trojan.Win32.Ekstak.hxea is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.hxea virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key

How to determine Trojan.Win32.Ekstak.hxea?


File Info:

crc32: C2E4E34A
md5: a5e4b32f3283a534996538160b7880f1
name: A5E4B32F3283A534996538160B7880F1.mlw
sha1: fcd99d15c925e9607412a5bf4c5d0ddb00cbf8b7
sha256: 1e118c100be43239a77f32b9a93cebeebfbf390f72954f0bcabdc682928e8017
sha512: 1ab3c567d69fda8fdd3d71193f8ea08535b9af0f0794c0846c9bf19e629683389c8ebce171b196a0f5562d43b7fea4cca968a97280fc81fc40310c7840d862f3
ssdeep: 24576:w7Uc0SbLHNOH4U+Ycv4MYmo2tvNirGz5TJR2Q3:K0Y64Tv4FGNJR26
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 1.0.0.0
ProductName: Resource Downloader
FileVersion: 1.0.0.0
Comments: This installation was built with Inno Setup.
FileDescription: Resource Downloader
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.hxea also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00537eb21 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3650
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MauvaisePMF.S19234567
ALYacApplication.Bundler.ICLoader.4.Gen
CylanceUnsafe
ZillyaAdware.Generic.Win32.115354
AlibabaTrojan:Win32/Ekstak.18cdb561
K7GWTrojan ( 0053896d1 )
Cybereasonmalicious.f3283a
CyrenW32/S-914d4b35!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GJBS
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyTrojan.Win32.Ekstak.hxea
BitDefenderApplication.Bundler.ICLoader.4.Gen
NANO-AntivirusTrojan.Win32.InstallCube.ffqcrz
MicroWorld-eScanApplication.Bundler.ICLoader.4.Gen
TencentTrojan.Win32.Kryptik.gjbs
Ad-AwareApplication.Bundler.ICLoader.4.Gen
SophosGeneric PUA PM (PUA)
ComodoApplication.Win32.ICLoader.GJ@7r8euk
TrendMicroPUA.Win32.ICLoader.SMA
McAfee-GW-EditionPacked-FHK!A5E4B32F3283
FireEyeGeneric.mg.a5e4b32f3283a534
EmsisoftApplication.Downloader (A)
SentinelOneStatic AI – Malicious PE
JiangminPacked.Katusha.dktz
WebrootW32.Adware.Gen
AviraTR/ICLoader.Gen8
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASBOL.C4FA
MicrosoftSoftwareBundler:Win32/ICLoader
ArcabitApplication.Bundler.ICLoader.4.Gen
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataWin32.Application.ICLoader.F
AhnLab-V3PUP/Win32.ICLoader.R232322
Acronissuspicious
McAfeePacked-FHK!A5E4B32F3283
MAXmalware (ai score=77)
VBA32Trojan.InstallCube
MalwarebytesAdware.InstallCube.BatBitRst
PandaTrj/Genetic.gen
TrendMicro-HouseCallPUA.Win32.ICLoader.SMA
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!5/u4OA7yi2A
IkarusPUA.Win32.ICLoader
MaxSecurePacked.Packed.WIN32.Katusha.gen_211985
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Trojan.Win32.Ekstak.hxea?

Trojan.Win32.Ekstak.hxea removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment