Trojan

UDS:Trojan.Win32.Ekstak.atnyy removal tips

Malware Removal

The UDS:Trojan.Win32.Ekstak.atnyy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan.Win32.Ekstak.atnyy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine UDS:Trojan.Win32.Ekstak.atnyy?


File Info:

name: EDA440B37DCB9C8B6D52.mlw
path: /opt/CAPEv2/storage/binaries/4ac6e4f3e563d7806b1d9421e8f4e5d2042f0927e940e157cbf4be5cd27c0b01
crc32: 9C2FD70F
md5: eda440b37dcb9c8b6d526e7c318f17c8
sha1: c2f933cc5bf4ad323c21b0d616660e53f1dfd673
sha256: 4ac6e4f3e563d7806b1d9421e8f4e5d2042f0927e940e157cbf4be5cd27c0b01
sha512: 4ddb31a3a206468a82c9e481c3b82edb6f008b114b742b66ac5a7ead45472f884ca200889df37a53a942de235bb9f353758b144a4091deb492050fec9cc83dd3
ssdeep: 196608:a3cY1EYyD9pq7Dga+rvPDHSg13++ERoYK+/v5wT4dD:a3cRqej7XDERDK+BdD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6663341BED1EA2BE420CF34A0A70B1B3A79EE0DBF23D11F1958F655AF3B1E40611656
sha3_384: d22d91eca7d4e37520b2ffa8c4240e93a536b77a15770d656bc335df9045ffe2a6d1a38254086d879a45edf70eafb203
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-12-25 08:06:42

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: DB Standard Console Setup
FileVersion:
LegalCopyright:
ProductName: DB Standard Console
ProductVersion: 1.2.2.5
Translation: 0x0000 0x04b0

UDS:Trojan.Win32.Ekstak.atnyy also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.ObfuscatedPoly.vc
McAfeeArtemis!EDA440B37DCB
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyUDS:Trojan.Win32.Ekstak.atnyy
AvastFileRepMalware [Adw]
DrWebTrojan.Siggen22.51773
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmUDS:Trojan.Win32.Ekstak.atnyy
FortinetW32/Agent.SLC!tr
AVGFileRepMalware [Adw]

How to remove UDS:Trojan.Win32.Ekstak.atnyy?

UDS:Trojan.Win32.Ekstak.atnyy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment