Malware

Generik.ETEEXLS removal

Malware Removal

The Generik.ETEEXLS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.ETEEXLS virus can do?

  • Starts servers listening on 0.0.0.0:5050
  • Unconventionial binary language: Ukrainian
  • Unconventionial language used in binary resources: Ukrainian
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Binary compilation timestomping detected

How to determine Generik.ETEEXLS?


File Info:

name: 33EF87FBDD92E8CBD9E5.mlw
path: /opt/CAPEv2/storage/binaries/1d5847109d21844defd7c1bde9802d9183fc300bb19a37355e30256c7ae98660
crc32: 9A3E1092
md5: 33ef87fbdd92e8cbd9e5388201a70894
sha1: 2475346c51a759ccfe974abe62cb3841fd6d99ea
sha256: 1d5847109d21844defd7c1bde9802d9183fc300bb19a37355e30256c7ae98660
sha512: 4278b4da49aee652b03bfd70c71e734f25adfed9e10c950bf7b5901b0dba452a7a49db74f7288f1581b2a6ac2caf93d438806b995337a72a6310b5a5c7fb98e0
ssdeep: 768:wgLp31GyNmnfJBpeen4151pM1CkPG5d7iM+PHMEtol92:wcoimr8en4fpMXPepitPltI92
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BD232A097C53C073E41649B1879686C16FBF6C1337E7A03FEF54018E5AB12984AAAAF5
sha3_384: 8d8d5d50f13160a057a827f33221a3a1302df0bc21be22485f2ac143f3d3f22df01294490ef3a5829915820af94e6838
ep_bytes: e887160000e916feffff558bec81ec28
timestamp: 2043-05-26 17:19:20

Version Info:

Comments: Sochet server
CompanyName: Alexandr Boichenko
FileDescription: Socket server
FileVersion: 1, 0, 0, 1
InternalName: TCPServer
LegalCopyright: Copyright (C) 2008 Alexandr Boichenko
OriginalFilename: TCPServer
ProductName: TCPServer
ProductVersion: 1, 0, 0, 1
Translation: 0x0422 0x04b0

Generik.ETEEXLS also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Trojan.Backdoor2.cq0@aGMoyBak
FireEyeGeneric.mg.33ef87fbdd92e8cb
ALYacGen:Trojan.Backdoor2.cq0@aGMoyBak
CylanceUnsafe
SangforTrojan.Win32.Occamy.C1D
Cybereasonmalicious.bdd92e
BitDefenderThetaGen:NN.ZexaCO.34062.cq0@aGMoyBak
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.ETEEXLS
TrendMicro-HouseCallTROJ_GEN.R002C0PKJ21
Paloaltogeneric.ml
BitDefenderGen:Trojan.Backdoor2.cq0@aGMoyBak
NANO-AntivirusTrojan.Win32.Mlw.exhfkf
AvastWin32:Malware-gen
TencentWin32.Backdoor.Agent.Llhv
Ad-AwareGen:Trojan.Backdoor2.cq0@aGMoyBak
SophosMal/Generic-S
ComodoMalware@#37wajsbfq6tn3
VIPREBehavesLike.Win32.Malware.rwx (mx-v)
TrendMicroTROJ_GEN.R002C0PKJ21
McAfee-GW-EditionRDN/Generic BackDoor
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Trojan.Backdoor2.cq0@aGMoyBak (B)
APEXMalicious
GDataGen:Trojan.Backdoor2.cq0@aGMoyBak
MicrosoftTrojan:Win32/Occamy.C1D
AhnLab-V3Backdoor/Win.Generic.C4807690
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=98)
VBA32BScope.Trojan.Injuke
IkarusGen.Win32.Backdoor
eGambitUnsafe.AI_Score_93%
FortinetGenerik.ETEEXLS!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Generik.ETEEXLS?

Generik.ETEEXLS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment