Trojan

About “UDS:Trojan.Win32.Ekstak.apsmf” infection

Malware Removal

The UDS:Trojan.Win32.Ekstak.apsmf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan.Win32.Ekstak.apsmf virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine UDS:Trojan.Win32.Ekstak.apsmf?


File Info:

name: E1D872AE1B0575B5286E.mlw
path: /opt/CAPEv2/storage/binaries/190a689d5967c71d0c80373c7da2a5c2175faacaa2d92a606bdf20184d3630f9
crc32: 4F283930
md5: e1d872ae1b0575b5286e353a20eae2cb
sha1: dc3a96fffbde510aefc88be2bb0cee94baf2f812
sha256: 190a689d5967c71d0c80373c7da2a5c2175faacaa2d92a606bdf20184d3630f9
sha512: f77f4ce88bbfbffd81c618490f478dbdfea8179f7be9f427f261a2ad81aa0f1a60e9e72f39575c00e682f62f7d726c14f4052970c9a842e381ff258a87660d06
ssdeep: 196608:QJMebiZAT5XOkKUyFzrEFajdmqGqRdcLlOd:BAhOkJypr1j/Gq7Ge
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A6633E712AA4CB6FDB86273EC4C6194B97A65188D311E1929EC4CFC27F5743922334E
sha3_384: 1a0cdd25feca12c40283c499e775de8ff9912388c761ce1d150091587298369938266217085c35a23331b2a4bc6d06c2
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-11-14 21:03:43

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Arium team
FileDescription: Arium Setup
FileVersion:
LegalCopyright:
ProductName: Arium
ProductVersion:
Translation: 0x0000 0x04b0

UDS:Trojan.Win32.Ekstak.apsmf also known as:

BkavW32.AIDetectMalware
DrWebTrojan.PWS.Stealer.29702
SkyhighArtemis!Trojan
McAfeeArtemis!E1D872AE1B05
CrowdStrikewin/malicious_confidence_60% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyUDS:Trojan.Win32.Ekstak.apsmf
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
AviraTR/Drop.Agent.lkpym
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmUDS:Trojan.Win32.Ekstak.apsmf
CynetMalicious (score: 100)
Cylanceunsafe
AVGFileRepMalware [Adw]
AvastFileRepMalware [Adw]

How to remove UDS:Trojan.Win32.Ekstak.apsmf?

UDS:Trojan.Win32.Ekstak.apsmf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment