Trojan

What is “Trojan:Win32/Ekstak.CB!MTB”?

Malware Removal

The Trojan:Win32/Ekstak.CB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ekstak.CB!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Behavior consistent with a dropper attempting to download the next stage.
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
static.17.249.201.195.clients.your-server.de

How to determine Trojan:Win32/Ekstak.CB!MTB?


File Info:

crc32: 58965DC3
md5: e575eea4f256d3876633591781764e72
name: E575EEA4F256D3876633591781764E72.mlw
sha1: f14b721f80747ae9644372bb2ad4a595ffa547ac
sha256: 5ed6626fb5ccd949276484c783fa9b5e8ce8dbc5cd01e9b79a319cbfb7b3f9c2
sha512: ced8745c9b2f22ab797efe11f39557594a4d21d604b3de876abb6a4a5f8573e7a8b2d1d5a93b7180c6cb439c5c166a1d94e5a69b075000bfbfb34095c6f6783f
ssdeep: 98304:10ccqeQgjWm3lVaxhUnMCeA2vcOJAtxp6rm3O:Hzd0WclVmhU1eA2nALorc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2005-2018 MODJO. All rights reserved.
FileVersion: 10, 2, 0, 6526
CompanyName: MODJO
ProductName: MODJO Internet Security
ProductVersion: 10, 2, 0, 6526
FileDescription: MODJO Internet Security
Translation: 0x0409 0x04e4

Trojan:Win32/Ekstak.CB!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0053e8521 )
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.SelfdelPMF.S4247483
ALYacGen:Variant.Zusy.307485
CylanceUnsafe
ZillyaTrojan.Ekstak.Win32.15803
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Ekstak.587d0bef
K7GWTrojan ( 0053e8521 )
Cybereasonmalicious.4f256d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GMIQ
APEXMalicious
AvastWin32:ICLoader-X [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.307485
NANO-AntivirusTrojan.Win32.InstallCube.fjvtjl
MicroWorld-eScanGen:Variant.Zusy.307485
TencentWin32.Trojan.Ekstak.Ajuz
Ad-AwareGen:Variant.Zusy.307485
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GS@84429a
BitDefenderThetaGen:NN.ZexaF.34236.@t0@aiPll0di
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
FireEyeGeneric.mg.e575eea4f256d387
EmsisoftGen:Variant.Zusy.307485 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/ICLoader.Gen8
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.299576D
MicrosoftTrojan:Win32/Ekstak.CB!MTB
ZoneAlarmHEUR:Packed.Win32.Katusha.gen
GDataGen:Variant.Zusy.307485
AhnLab-V3PUP/Win32.FileTour.R242805
Acronissuspicious
McAfeePacked-FME!E575EEA4F256
MAXmalware (ai score=89)
VBA32BScope.Trojan.Ekstak
MalwarebytesAdware.Agent
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!3sLpyh1IcJc
IkarusPUA.ICLoader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:ICLoader-X [Adw]
Paloaltogeneric.ml

How to remove Trojan:Win32/Ekstak.CB!MTB?

Trojan:Win32/Ekstak.CB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment