Virus

How to remove “Virus:Win32/Geksone.EC!MTB”?

Malware Removal

The Virus:Win32/Geksone.EC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Geksone.EC!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Geksone.EC!MTB?


File Info:

name: 5AA7B8C87A1AC069BFC5.mlw
path: /opt/CAPEv2/storage/binaries/8f69b21dd094f62ea451b5d606c7a72ef7685d85ae9d401c9689d3789cde8e24
crc32: E1AE0DD8
md5: 5aa7b8c87a1ac069bfc5b94a33582ed5
sha1: bef9570f9636f57d3eecfffbb0240d80b079957a
sha256: 8f69b21dd094f62ea451b5d606c7a72ef7685d85ae9d401c9689d3789cde8e24
sha512: b3b3505d242a0c7dcef5d6391a011448c704dc8a1f7b2d01398873f21c2ad5696299885eac6a078a8e73fbaaeab4bbe62ef6887e2bff55a8fd1d4c85715c212a
ssdeep: 192:BRjwmodVe4yXMR/4SdAe12d74orQXqIRJ9umZBdZDsCCVoUl/EsUFWeuS49Ryys2:BRjgbyaedmlyroY/byysRZrh1orjwhc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15B439393D490B5DBC441C17EB06C86F9B72FD40D1B90AC09A582F5AFAEE89C25F1A21D
sha3_384: 62982402bd1732562f792e791f5643b055cb9bbb727801196017ab53a03306800606631aacf90574f53d098e7f6198c6
ep_bytes: 609ce8000000005d81ed071040008db5
timestamp: 2004-03-30 13:04:12

Version Info:

Comments:
CompanyName: Smart Link
FileDescription: SLRunDll
FileVersion: 3.80.01MC15
InternalName: SLRunDll
LegalCopyright: All rights reserved
LegalTrademarks:
OriginalFilename: SLRunDll.dll
PrivateBuild:
ProductName: Soft Modem
ProductVersion: 3.80.01MC15
SpecialBuild:
Translation: 0x0000 0x04b0

Virus:Win32/Geksone.EC!MTB also known as:

BkavW32.GeksoneHQcA.PE
LionicVirus.Win32.Crytex.lJfl
Elasticmalicious (high confidence)
ClamAVWin.Virus.Hublo-1
SkyhighBehavesLike.Win32.Infected.qt
ALYacWin32.Crytex.A
Cylanceunsafe
VIPREWin32.Crytex.A
SangforVirus.Win32.Geksone.Vrve
K7AntiVirusVirus ( 0040f5911 )
BitDefenderWin32.Crytex.A
K7GWVirus ( 0040f5911 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Crytex.A
BaiduWin32.Virus.Crytex.a
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Geksone.B
APEXMalicious
CynetMalicious (score: 99)
KasperskyVirus.Win32.Crytex.1290
AlibabaVirus:Win32/Geksone.b8452497
NANO-AntivirusVirus.Win32.Crytex.bzelsx
MicroWorld-eScanWin32.Crytex.A
TencentVirus.Win32.Crytex.a
SophosW32/NGVCK-W
F-SecureMalware.W32/Crytex.1290
DrWebWin32.Siggen.15
ZillyaVirus.Geksone.Win32.1
TrendMicroPE_CRYTEX.A
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.5aa7b8c87a1ac069
EmsisoftWin32.Crytex.A (B)
SentinelOneStatic AI – Suspicious PE
VaristW32/Crytex.1290
AviraW32/Crytex.1290
MAXmalware (ai score=80)
Antiy-AVLVirus/Win32.Crytex.1290
KingsoftWin32.Infected.AutoInfector.a
XcitiumVirus.Win32.Crytex.1290@4wzy41
MicrosoftVirus:Win32/Geksone.EC!MTB
ZoneAlarmVirus.Win32.Crytex.1290
GDataWin32.Virus.Golem.A
GoogleDetected
McAfeeArtemis!5AA7B8C87A1A
DeepInstinctMALICIOUS
VBA32Virus.Win32.Crytex.1290
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallPE_CRYTEX.A
RisingVirus.Geksone!1.AD16 (CLASSIC)
IkarusVirus.Win32.Crytex
MaxSecureVirus.W32.Crytex.1290
FortinetW32/Geksone.B
BitDefenderThetaGen:NN.ZexaF.36802.du0@aWXIreni
AVGWin32:Cryte
Cybereasonmalicious.87a1ac
AvastWin32:Cryte
alibabacloudVirus:Win/Hublo.A(dyn)

How to remove Virus:Win32/Geksone.EC!MTB?

Virus:Win32/Geksone.EC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment