Trojan

Trojan:Win32/Ekstak.ASEM!MTB removal guide

Malware Removal

The Trojan:Win32/Ekstak.ASEM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ekstak.ASEM!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Ekstak.ASEM!MTB?


File Info:

name: BE3C4F0CB0D88DD149B0.mlw
path: /opt/CAPEv2/storage/binaries/846985ceca6d7d38e2931ea4271ecc7b2d84050efdbb3d1022209e8364a45ebc
crc32: 7A6984DA
md5: be3c4f0cb0d88dd149b093e1dc1cc4b4
sha1: ba063f464e69a4a2b3db81d7b5954c40b5147160
sha256: 846985ceca6d7d38e2931ea4271ecc7b2d84050efdbb3d1022209e8364a45ebc
sha512: 0d6840fa716cc47bf8cbe09ae3c7980a6890a8a00433dc480bfabd525ca8553ca29b6d572f0fc398b6fc1908ca9a4e9a1a7e5eade69620eeccf1e6b977adda7e
ssdeep: 196608:uLhxysHXnZxfvTPGxMdh3//q54pEXS4K6wSEgwAA4gGUEgJ:uLhxfxYMdVg42X3KX8wZ40tJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB8633C04DF3CFA4F684973AA0CF0AACA5E3C41368555257D61E495F3A777F2AC24A22
sha3_384: 62648033052806a9b145bb5446b4c338975df530ff9c3def8fafd54942dec06b0db5a992dee96c55909a26c66814bd53
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2024-01-13 20:56:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Python compress station Setup
FileVersion:
LegalCopyright:
ProductName: Python compress station
ProductVersion:
Translation: 0x0000 0x04b0

Trojan:Win32/Ekstak.ASEM!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
Cylanceunsafe
SangforDropper.Win32.Ekstak.Vzlu
AlibabaTrojanDropper:Win32/Ekstak.73c910ca
CrowdStrikewin/malicious_confidence_70% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Ekstak.auzud
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Iajl
TrendMicroTROJ_GEN.R002C0DAJ24
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
GDataWin32.Backdoor.Bodelph.EJHJ57
ZoneAlarmTrojan.Win32.Ekstak.auzud
MicrosoftTrojan:Win32/Ekstak.ASEM!MTB
VaristW32/Trojan.KVSE-4743
AhnLab-V3Trojan/Win.Malware-gen.C5576183
McAfeeArtemis!BE3C4F0CB0D8
MalwarebytesTrojan.Dropper.EKS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DAJ24
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Ekstak.ASEM!MTB?

Trojan:Win32/Ekstak.ASEM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment