Trojan

Trojan:Win32/Ekstak.CF!MTB removal guide

Malware Removal

The Trojan:Win32/Ekstak.CF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ekstak.CF!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Ekstak.CF!MTB?


File Info:

crc32: 684A580B
md5: 0b9862d3e6dc6fcbf241b0ebe2be50e0
name: exloader-1dd668d.exe
sha1: 16737a513d06ff859bc3e66e5633217944059f2a
sha256: 0811ef42a6eb9a0d01de562af1de5dd27b82d4e5969792d77b4ce0b8fecd50b0
sha512: d5e93e82171f6b8378b76f94a3593eb84ded7b3965570b05e750b16f35e879e32ad8265c9c4999a7f85db9eaabdd1ca42df7f04c2f0cbb5b75ade440f9d7e600
ssdeep: 49152:6IuNDqzUpLjcya0JJmlRP28g2mTrgF2OHaxRJD:6PRlIya0r22FVIf6xf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 5.1.2.456
CompanyName: Complex New Technologies
Comments: This installation was built with Inno Setup.
ProductName: JetBee
ProductVersion: 5.1.2.456
FileDescription: JetBee Setup
Translation: 0x0000 0x04b0

Trojan:Win32/Ekstak.CF!MTB also known as:

MicroWorld-eScanTrojan.Agent.EIDY
FireEyeTrojan.Agent.EIDY
McAfeeGenericR-RLU!0B9862D3E6DC
ALYacTrojan.Agent.EIDY
CylanceUnsafe
K7AntiVirusTrojan ( 0055c28c1 )
BitDefenderTrojan.Agent.EIDY
K7GWTrojan ( 0055c28c1 )
BitDefenderThetaGen:NN.ZexaCO3.32515.vw0@aGlQYvfk
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Adware-gen [Adw]
GDataTrojan.Agent.EIDY
AlibabaTrojan:Win32/Ekstak.db8af9c4
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
Endgamemalicious (moderate confidence)
SophosTroj/Agent-BDBB
F-SecureTrojan.TR/Crypt.Agent.nkaus
DrWebTrojan.DownLoader30.45745
ZillyaTrojan.Kryptik.Win32.1862906
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.nkaus
MAXmalware (ai score=81)
ArcabitTrojan.Agent.EIDY
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Ekstak.CF!MTB
AhnLab-V3Malware/Win32.RL_Generic.R301299
Acronissuspicious
VBA32BScope.Trojan.Ekstak
Ad-AwareTrojan.Agent.EIDY
MalwarebytesAdware.DLAssistant
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.GYUK
SentinelOneDFI – Suspicious PE
FortinetW32/GenKryptik.DYKG!tr
AVGWin32:Adware-gen [Adw]

How to remove Trojan:Win32/Ekstak.CF!MTB?

Trojan:Win32/Ekstak.CF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment