Trojan

What is “Trojan:Win32/Ekstak.ASES!MTB”?

Malware Removal

The Trojan:Win32/Ekstak.ASES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ekstak.ASES!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Ekstak.ASES!MTB?


File Info:

name: 3536FB143A06A1618D19.mlw
path: /opt/CAPEv2/storage/binaries/810c069103904dd861329b82da985ff9e26742e39a9169e9546795663e46ece4
crc32: 9080CD87
md5: 3536fb143a06a1618d198f649559bbd2
sha1: 2fb585d45747e63b253587e1d40827cd8394bb76
sha256: 810c069103904dd861329b82da985ff9e26742e39a9169e9546795663e46ece4
sha512: 737d6954226591f82e765d3781b18e13d62e95a1a1c92a0d8372981fdeb494588d16d467589eb7eba01d4a85a0e696fe9091ad8eb9703d3495930eb819c93fad
ssdeep: 98304:cgNQdR8i+5mPgPcRP4mN9YjOvHkgFAICxosJd+qGbO/RzaKF//:2dCJ5mPgPcRPcOvRtLFbU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A916331CAA857477EAF145794E16D05E0E9BF4323C76A11E331988BD1F7B7F0A80A70A
sha3_384: 82c30ae6c396143108f62cd4322f7deac29d6b8ac810f540b65e83acc3f349e799a9190f6db0f3a94357109b827b4b69
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2024-01-19 18:02:56

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: HTML to CSV Converter Setup
FileVersion:
LegalCopyright:
ProductName: HTML to CSV Converter
ProductVersion: 0.1.1.9
Translation: 0x0000 0x04b0

Trojan:Win32/Ekstak.ASES!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.34713212
FireEyeTrojan.Generic.34713212
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
ALYacTrojan.Generic.34713212
Cylanceunsafe
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Ekstak.54b085b7
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.avdqy
BitDefenderTrojan.Generic.34713212
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Fajl
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Nekark.qotqz
VIPRETrojan.Generic.34713212
TrendMicroTROJ_GEN.R002C0XAP24
EmsisoftTrojan.Generic.34713212 (B)
IkarusTrojan-Dropper.Win32.Agent
GDataTrojan.Generic.34713212
AviraTR/AD.Nekark.qotqz
VaristW32/Agent.TNLQ-8039
ArcabitTrojan.Generic.D211AE7C
ZoneAlarmTrojan.Win32.Ekstak.avdqy
MicrosoftTrojan:Win32/Ekstak.ASES!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Malware-gen.R632118
McAfeeArtemis!3536FB143A06
MAXmalware (ai score=85)
MalwarebytesMalware.AI.3626129961
TrendMicro-HouseCallTROJ_GEN.R002C0XAP24
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.226687820.susgen
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Ekstak.ASES!MTB?

Trojan:Win32/Ekstak.ASES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment