Home Malware Programs Trojans Trojan.Ekstak

Trojan.Ekstak

Posted: September 12, 2017

Threat Metric

Ranking: 6,754
Threat Level: 8/10
Infected PCs: 236,081
First Seen: September 12, 2017
Last Seen: March 10, 2025
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\lsid10015.exe File name: lsid10015.exe
Size: 1.11 MB (1118208 bytes)
MD5: 9dd5051b7b0eb0c0676f55057b6c05b2
Detection count: 375
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\btscservice\btscservice.exe File name: btscservice.exe
Size: 1.48 MB (1483992 bytes)
MD5: c97e6e4a1c87d6bc15d51509a5973a13
Detection count: 185
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\btscservice
Group: Malware file
Last Updated: October 3, 2018
%ALLUSERSPROFILE%\lsid25038.exe File name: lsid25038.exe
Size: 1.11 MB (1110720 bytes)
MD5: 98eb4915b82a1bdcdaaa277c18a43655
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid49472.exe File name: lsid49472.exe
Size: 1.11 MB (1110720 bytes)
MD5: 8265acba0f958ee979debb5048a9b2a3
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid40358.exe File name: lsid40358.exe
Size: 1.03 MB (1036288 bytes)
MD5: 0aca6e95c2f52ac4076e0061ae9599c7
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid11092.exe File name: lsid11092.exe
Size: 1.11 MB (1110720 bytes)
MD5: 4d427c31dec5e1e213527b6871023382
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid16037.exe File name: lsid16037.exe
Size: 1.11 MB (1118208 bytes)
MD5: ce32207dcf31bb60445d5176ec33f5f0
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid9247.exe File name: lsid9247.exe
Size: 1.1 MB (1105920 bytes)
MD5: 1d00588cd8dbc3291d7e9716defabcca
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid38160.exe File name: lsid38160.exe
Size: 1.03 MB (1036288 bytes)
MD5: 30fbe4cf3a42afff4291a72444ea6b3e
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid16569.exe File name: lsid16569.exe
Size: 1.1 MB (1105920 bytes)
MD5: 2c505bcc82683afe7afbe20b73775a6a
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid40201.exe File name: lsid40201.exe
Size: 1.03 MB (1032192 bytes)
MD5: 266b65a47e00539150c7fc976570836d
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid4273.exe File name: lsid4273.exe
Size: 1.03 MB (1032192 bytes)
MD5: 356e5289ca51fe895a94d4270d9d6aed
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid54053.exe File name: lsid54053.exe
Size: 1.03 MB (1036288 bytes)
MD5: f290786ae4435c61195ed8db5f52b115
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid30300.exe File name: lsid30300.exe
Size: 1.03 MB (1032192 bytes)
MD5: b55a58160b8c6c579492b58643fc9ad1
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid29267.exe File name: lsid29267.exe
Size: 1.03 MB (1032192 bytes)
MD5: 794dc48c78acb850fb79d311d0b2117e
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid37460.exe File name: lsid37460.exe
Size: 1.04 MB (1040384 bytes)
MD5: f6b792175a34510c8886380ea9e8453f
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid34534.exe File name: lsid34534.exe
Size: 1.03 MB (1032192 bytes)
MD5: 4aa182ef2504dddd7e9d1c8441a9c9a4
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid14324.exe File name: lsid14324.exe
Size: 1.03 MB (1036288 bytes)
MD5: 3076a7df2e2bf7becd873f04d3b9b85e
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\lsid57096.exe File name: lsid57096.exe
Size: 1.11 MB (1110720 bytes)
MD5: cd955e65265d842e292a34b7f889c04a
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 12, 2017
%ALLUSERSPROFILE%\Anwendungsdaten\lsid923.exe File name: lsid923.exe
Size: 1.03 MB (1032192 bytes)
MD5: 72935090baedbb804298af84ca2c97ac
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Anwendungsdaten
Group: Malware file
Last Updated: September 12, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\Application Data\betaservice\betaservice.exe%ALLUSERSPROFILE%\Application Data\localnetservice\localnetservice.exe%ALLUSERSPROFILE%\Application Data\WinSx[RANDOM CHARACTERS].exe%ALLUSERSPROFILE%\betaservice\betaservice.exe%ALLUSERSPROFILE%\c{0,1}lsid[NUMBERS].exe%ALLUSERSPROFILE%\KeService.exe%ALLUSERSPROFILE%\localnetservice\localnetservice.exe%ALLUSERSPROFILE%\SecureIM.exe%ALLUSERSPROFILE%\vshub.exe%ALLUSERSPROFILE%\WinSx[RANDOM CHARACTERS].exeHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}dahiService

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\btscService%ALLUSERSPROFILE%\Application Data\cpafService%ALLUSERSPROFILE%\Application Data\dagfservice%ALLUSERSPROFILE%\Application Data\dahcService%ALLUSERSPROFILE%\Application Data\dahhService%ALLUSERSPROFILE%\Application Data\dahiService%ALLUSERSPROFILE%\Application Data\dahjService%ALLUSERSPROFILE%\Application Data\dahkService%ALLUSERSPROFILE%\Application Data\ellfService%ALLUSERSPROFILE%\aaagService%ALLUSERSPROFILE%\btscService%ALLUSERSPROFILE%\cpafService%ALLUSERSPROFILE%\dadzService%ALLUSERSPROFILE%\daflService%ALLUSERSPROFILE%\dafwservice%ALLUSERSPROFILE%\dagcService%ALLUSERSPROFILE%\dagfservice%ALLUSERSPROFILE%\daggservice%ALLUSERSPROFILE%\daglService%ALLUSERSPROFILE%\dagoService%ALLUSERSPROFILE%\dahaService%ALLUSERSPROFILE%\dahcService%ALLUSERSPROFILE%\dahhService%ALLUSERSPROFILE%\dahiService%ALLUSERSPROFILE%\dahjService%ALLUSERSPROFILE%\dahkService%ALLUSERSPROFILE%\ellfService%PROGRAMFILES(x86)%\ViewFD%programfiles%\ViewFD
Loading...