Trojan

Trojan:Win32/Ekstak!pz removal guide

Malware Removal

The Trojan:Win32/Ekstak!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ekstak!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Ekstak!pz?


File Info:

name: 232725A292AAE6F6A419.mlw
path: /opt/CAPEv2/storage/binaries/ebff52b569e3c2904aabb5188b7ea17206460451fc7b97558101026e7d996691
crc32: 55FBF8AA
md5: 232725a292aae6f6a4195ff063fc8cb6
sha1: be1dde0e98f0dd5c3f51b05c79347623460b9d7a
sha256: ebff52b569e3c2904aabb5188b7ea17206460451fc7b97558101026e7d996691
sha512: 5c1f3ed573098583ef9f249fe3fec94f2695e624d099471ae26fa2625cdb90b2d8b4b130d264a57621a97ec30cc282d3150505170c36f9525f002595a9e59061
ssdeep: 98304:3ekpvgx6dv1gjAAeFA9DyN1D3wmUmSCAveFvHBN2ZwojjVDHUVrgZd:O8gx6Re9k1D3dUmRYehT2ZwgjVrUxgd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150563302E242213FF1E49E748E25E00736BBBE1961B664694689E84A5B7531FCD7F3F0
sha3_384: 8b6b6aa7e2f04d44bbb52b63fb6625b7bb824222db92355516dd7c7ec82544ecc9bf1306183a31ce5b789a23ca8c74b8
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-11-26 19:34:56

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: MIXAudio Setup
FileVersion:
LegalCopyright:
ProductName: MIXAudio
ProductVersion:
Translation: 0x0000 0x04b0

Trojan:Win32/Ekstak!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
DrWebTrojan.Siggen22.51644
SkyhighBehavesLike.Win32.ObfuscatedPoly.tc
McAfeeArtemis!232725A292AA
Cylanceunsafe
ZillyaTrojan.Ekstak.Win32.75035
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.8edaf909
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Generic-10015776-0
KasperskyTrojan.Win32.Ekstak.apwll
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Cwnw
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0DLP23
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojan.Ekstak.cihn
VaristW32/Ekstak.JK.gen!Eldorado
MicrosoftTrojan:Win32/Ekstak!pz
ZoneAlarmTrojan.Win32.Ekstak.apwll
GDataWin32.Trojan.Agent.1R0O01
AhnLab-V3Trojan/Win.DownloadAssistant.R622897
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002C0DLP23
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.220933856.susgen
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Ekstak!pz?

Trojan:Win32/Ekstak!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment