Virus

Virus:Win32/Geksone.EC!MTB (file analysis)

Malware Removal

The Virus:Win32/Geksone.EC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Geksone.EC!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Geksone.EC!MTB?


File Info:

name: B0E7E38F8D212578BC5F.mlw
path: /opt/CAPEv2/storage/binaries/6b8f3a4c80879c0d8b47337ed2fab78daa17d7200b3211a8292b853b33cdfcb2
crc32: 9186877B
md5: b0e7e38f8d212578bc5f77458b504171
sha1: 92008f0c0efae91a09122d5710bcc6b1a37f271c
sha256: 6b8f3a4c80879c0d8b47337ed2fab78daa17d7200b3211a8292b853b33cdfcb2
sha512: 201cd0130777d0fb20da40b483059031fcc58455a4032c59f25c71a419800b5e31c6e5d4784db6ddc83a1b2f14c0916e7271445595312fc52217f5ee1a8eb0c7
ssdeep: 384:l7Cb6fqzDLMZi9N+fmWN0WLW6ZwLWW29i8AKaRv4Igr3W5:9CbhN2FBW78A/RvyA
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15BB29C0162E83114E1B237B0C4F595B586233850DAB8D27D3BEDD5CE2BA3922ADE3757
sha3_384: 53bd0a4b718d0d4256f9aaaa9bb0482ff99d646ae575496434e2509d74755a2dd1037433925c1d31a7daf74970ec5e6a
ep_bytes: 609ce8000000005d81ed071040008db5
timestamp: 2001-08-17 20:57:08

Version Info:

CompanyName: Microsoft Corporation
FileDescription: TCP/IP Route Command
FileVersion: 5.1.2600.0 (xpclient.010817-1148)
InternalName: route.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: route.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.0
Translation: 0x0409 0x04b0

Virus:Win32/Geksone.EC!MTB also known as:

BkavW32.GeksoneHQcA.PE
LionicVirus.Win32.Crytex.lJfl
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Crytex.A
FireEyeGeneric.mg.b0e7e38f8d212578
SkyhighBehavesLike.Win32.Virut.mm
McAfeeArtemis!B0E7E38F8D21
VIPREWin32.Crytex.A
SangforVirus.Win32.Crytex.V1iu
K7AntiVirusVirus ( 0040f5911 )
AlibabaVirus:Win32/Geksone.00a58470
K7GWVirus ( 0040f5911 )
Cybereasonmalicious.f8d212
BitDefenderThetaGen:NN.ZexaF.36802.bq0@aGZkrlmi
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Geksone.B
APEXMalicious
CynetMalicious (score: 99)
KasperskyVirus.Win32.Crytex.1290
BitDefenderWin32.Crytex.A
NANO-AntivirusVirus.Win32.Crytex.bzelsx
AvastWin32:Cryte
RisingVirus.Geksone!1.AD16 (CLASSIC)
EmsisoftWin32.Crytex.A (B)
BaiduWin32.Virus.Crytex.a
F-SecureMalware.W32/Crytex.1290
DrWebWin32.Siggen.15
ZillyaVirus.Geksone.Win32.1
TrendMicroPE_CRYTEX.A
SophosW32/NGVCK-W
SentinelOneStatic AI – Malicious PE
GDataWin32.Virus.Golem.A
VaristW32/Crytex.1290
AviraW32/Crytex.1290
MAXmalware (ai score=85)
Antiy-AVLVirus/Win32.Crytex.1290
Kingsoftmalware.kb.a.1000
XcitiumVirus.Win32.Crytex.1290@4wzy41
ArcabitWin32.Crytex.A
ZoneAlarmVirus.Win32.Crytex.1290
MicrosoftVirus:Win32/Geksone.EC!MTB
GoogleDetected
Acronissuspicious
VBA32Virus.Win32.Crytex.1290
ALYacWin32.Crytex.A
Cylanceunsafe
TrendMicro-HouseCallPE_CRYTEX.A
TencentVirus.Win32.Crytex.a
IkarusVirus.Win32.Virut
MaxSecureVirus.W32.Crytex.1290
FortinetW32/Geksone.B
AVGWin32:Cryte
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirus:Win/Hublo.A(dyn)

How to remove Virus:Win32/Geksone.EC!MTB?

Virus:Win32/Geksone.EC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment