Trojan

Trojan:Win32/Ekstak.ASEB!MTB removal guide

Malware Removal

The Trojan:Win32/Ekstak.ASEB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ekstak.ASEB!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Ekstak.ASEB!MTB?


File Info:

name: B750CD66634C1B03BD1D.mlw
path: /opt/CAPEv2/storage/binaries/b4bb7e069a749665cc0e24493e2911723b72b18dfee9b10e46e157ec65b13137
crc32: 4508D494
md5: b750cd66634c1b03bd1da98a2a16e9b2
sha1: 65502eb5882ef2b27e56ae75e0ac8a2f5891bfb8
sha256: b4bb7e069a749665cc0e24493e2911723b72b18dfee9b10e46e157ec65b13137
sha512: b637c59bf1d96e8fb2100ef7f63384a540f5b710db4f82dda0f2f7d74543d7fbd03459ee62978f0bb267590d0fd9d0a5dba2a0bb0fecaa8e72a1de76697fa455
ssdeep: 98304:68MuNTRKmZXC8OZTkfLaSFbf+k+dKmhd0T7AnlOyTXg8v2xqaqGMwGs2E4dm8:yuq8OZTk+SJmCTUnlZE8y7kw52E4dD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11C66330D89202231D50696B39FABEF65DE67373FCAA46DFA611C634F92B23D0C110799
sha3_384: 163573ffcfcd13e4b37b2934e4a0c1b9d62357502dd14978f01f108d644b264dff615ab929487c4d67b2ac940ca8178f
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-12-24 11:10:37

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: HTMLPumpVBLIB Setup
FileVersion:
LegalCopyright:
ProductName: HTMLPumpVBLIB
ProductVersion: 1.2.2.4
Translation: 0x0000 0x04b0

Trojan:Win32/Ekstak.ASEB!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
SkyhighBehavesLike.Win32.ObfuscatedPoly.vc
McAfeeArtemis!B750CD66634C
MalwarebytesTrojan.Dropper.EKS
ZillyaTrojan.Ekstak.Win32.76415
SangforDropper.Win32.Ekstak.V2sq
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.9cb06303
K7GWTrojan ( 005722f11 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan.Win32.Ekstak.atgbl
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Cplw
F-SecureTrojan.TR/Drop.Agent.hrkzx
DrWebTrojan.Siggen22.51078
TrendMicroTROJ_GEN.R002C0DLU23
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
VaristW32/Agent.LQYY-1933
AviraTR/Drop.Agent.hrkzx
KingsoftWin32.Trojan.Ekstak.atgbl
MicrosoftTrojan:Win32/Ekstak.ASEB!MTB
ZoneAlarmTrojan.Win32.Ekstak.atgbl
GDataWin32.Trojan.Agent.AG8QU9
AhnLab-V3Trojan/Win.Malware-gen.C5566623
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLU23
YandexTrojan.Ekstak!japB0QU5zGc
MaxSecureTrojan.Malware.221897183.susgen
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Ekstak.ASEB!MTB?

Trojan:Win32/Ekstak.ASEB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment