Threat Database Trojans Trojan.Ekstak.DH

Trojan.Ekstak.DH

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,285
Threat Level: 80 % (High)
Infected Computers: 33,402
First Seen: July 26, 2021
Last Seen: July 2, 2026
OS(es) Affected: Windows

The detection of Trojan.Ekstak.DH on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise the integrity of your computer and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Ekstak.DH?

Trojan.Ekstak.DH is a type of malware that can infiltrate your system without your knowledge or consent. The name itself does not provide specific information about the malware family, but it is clear that it is a Trojan-type threat. Trojans are malicious programs that can disguise themselves as legitimate software, allowing them to bypass security measures and gain unauthorized access to your system.

How Trojan.Ekstak.DH Operates

Once installed, Trojan.Ekstak.DH can operate in the background, allowing an attacker to access your system remotely. This can lead to a range of malicious activities, including data theft, keystroke logging, and the installation of additional malware. The exact mechanisms used by Trojan.Ekstak.DH are not specified, but it is likely that it uses common Trojan tactics, such as exploiting vulnerabilities or using social engineering techniques to trick users into installing the malware.

Symptoms of Infection

Identifying the symptoms of a Trojan.Ekstak.DH infection can be challenging, as the malware is designed to operate stealthily. However, some common signs of infection include unusual system behavior, such as slow performance, unexpected crashes, or unfamiliar programs running in the background. You may also notice suspicious network activity or unexpected changes to your system settings. If you suspect that your system is infected, it is essential to take immediate action to remove the threat.

How to Remove Trojan.Ekstak.DH

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and identify all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Ekstak.DH from your system requires a combination of technical expertise and caution. By following the steps outlined above, you can help to ensure that your system is free from this malicious threat. However, it is also essential to take proactive measures to prevent future infections, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious when opening email attachments or downloading software from the internet. By staying vigilant and taking prompt action, you can help to protect your system and your personal data from the risks associated with Trojan.Ekstak.DH and other malware threats.

Analysis Report

General information

Family Name: Trojan.Ekstak.DH
Signature status: No Signature

Known Samples

MD5: 9223dc3e15767f8b6f7c284a3efafb13
SHA1: 715efca4a26d4f948809bf9dd64860ede314dde6
SHA256: 2FAE493AD5B0CA0A15C84D57D3438FBCD1016E87DD7770795D0D5BC28DCA3EA0
File Size: 2.68 MB, 2678783 bytes
MD5: 744040819b80efa04538c551c82b652f
SHA1: d37ce74ef8b75cb1e3cc21ec12da509537329f17
SHA256: 05857ACB60C0A7D89CA4BB84416BA90EC7C07EEFA36A0C774A7B0C9BABB8523B
File Size: 1.59 MB, 1589243 bytes
MD5: c42489605c55e9afa1b21acba572af59
SHA1: 02753362a6db383c897e4814ae7b9fde528eecae
SHA256: 4C75207FEF3CB194FC9B87924C5028A8DCA311883048EB96750896D97BF0FECF
File Size: 2.31 MB, 2314230 bytes
MD5: e0f89fc11a329ced108edc45c8885875
SHA1: b8a5eab523806e178b0eb90733cf1a8999d0c340
SHA256: 82224D3331A093C0A3077B22043C2D17BCDF7DFB84D976CDC6646BE1489E8265
File Size: 2.16 MB, 2161145 bytes
MD5: f26c76e6afa3464fe3d5bb4ff8ad27f3
SHA1: 5398fa7d337ccdfdaff4755aa9104b7d5e3186a7
SHA256: F41C706F47C0255C08F1E9842B097AD5BDC9E8F832B7AC0F94B33C8AE9CE1995
File Size: 3.50 MB, 3502080 bytes
Show More
MD5: 2b89c29a8d3cb3cf54b3f60cd1be85a6
SHA1: 89cc501a00a7070bc413923b125e396e79886d40
SHA256: 5B1B5C275E060C1E078C91074C01EAEBADA7E9E2B7D9BCAD8B7E681169B89F5A
File Size: 2.99 MB, 2985848 bytes
MD5: d48d2c30864a805e80da30047f608482
SHA1: 42b42131ec0e767d26c1e135dd1237e3b16bada8
SHA256: EDA85736E7D2C3600FC67AC2666014FDE452EA7E5C8CA2F265E3E8A161592876
File Size: 2.70 MB, 2695167 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments S.M.A.R.T. Assistant
Company Name
  • Exfm M. Ronim @ AbrLab
  • Exfq Q. Roniq @ AbvLab
  • MaxLim
  • Puran Software
File Description
  • DiskFresh by Puran Software
  • Library Games 1.1 Installation
  • S.M.A.R.T. Assistant
File Version
  • 1.4.3.16
  • 1.2.0.34
  • 1.1.4.135
  • 1.1
  • 1.0.2.26
  • 1.0.2.23
Internal Name
  • DiskFresh.exe
  • S.M.A.R.T. Assistant
Legal Copyright MaxLim
Legal Trademarks Exff F. Ronif
Original Filename
  • DiskFresh.exe
  • Exfm M. Ronim @ AbrLab
  • Exfq Q. Roniq @ AbvLab
  • SMARTAssistant
Product Name
  • DiskFresh
  • Personal Video Database
  • S.M.A.R.T. Assistant
Product Version
  • 1.4.3.16
  • 1.2.0.34
  • 1.0.2.26
  • 1.0.2.23
  • 0.0.4.135

File Traits

  • 2+ executable sections
  • HighEntropy
  • Installer Version
  • No Version Info
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 2,374
Potentially Malicious Blocks: 77
Whitelisted Blocks: 1,282
Unknown Blocks: 1,015

Visual Map

x 0 ? ? ? ? ? ? ? ? ? ? ? 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 ? 0 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x x 0 0 ? 0 ? ? 0 0 ? ? ? ? ? 0 ? 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x ? ? ? ? ? ? 0 ? ? x ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? x ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? x x 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? x ? ? ? ? ? 0 0 ? ? 0 ? ? ? 0 ? 0 ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? x ? ? ? ? ? 0 ? x ? ? ? 0 ? 0 ? ? ? x ? 0 0 ? ? ? ? ? ? ? ? ? 0 x ? ? 0 0 0 0 ? ? ? 0 0 x 0 x 0 ? ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? x 0 ? ? 0 0 0 0 ? ? x 0 ? ? ? ? ? 0 ? ? ? 0 x x ? ? ? ? ? ? ? ? 0 ? ? ? ? x ? x ? ? ? 0 ? ? 0 ? ? ? ? 0 x ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? x x ? ? 0 ? ? ? x ? ? x ? ? x ? ? ? ? ? ? ? ? ? ? 0 0 ? x x ? 0 0 ? ? x ? 0 0 ? ? ? ? ? ? ? 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? x 0 x ? ? ? 0 0 ? ? 0 ? x ? ? x ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? x ? ? ? ? 0 0 ? ? ? ? ? ? ? ? x ? 0 0 ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? ? 0 ? 0 0 0 x ? ? 0 0 ? ? 0 0 ? 0 x x ? ? ? ? ? ? ? ? ? ? x ? x x 0 0 ? 0 ? ? ? x 0 0 ? ? ? ? ? ? 0 ? ? 0 ? ? x 0 ? ? ? ? ? ? ? 0 0 0 0 ? ? ? ? ? ? x 0 ? ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? x x ? ? ? ? ? 0 0 0 0 ? ? ? 0 ? 0 0 0 ? ? ? 0 0 0 0 ? ? ? ? 0 0 ? 0 0 0 0 ? ? 0 0 ? 0 0 x ? 0 ? 0 ? 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 0 ? ? 0 0 ? ? 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? ? 0 x 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Network Winsock
  • gethostbyname
Keyboard Access
  • GetKeyState

Trending

Most Viewed

Loading...