Malware

WebToolbar.Win32.Estapa.heur information

Malware Removal

The WebToolbar.Win32.Estapa.heur is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WebToolbar.Win32.Estapa.heur virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Spanish (Mexican)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine WebToolbar.Win32.Estapa.heur?


File Info:

name: 0188C0021B9C2AA5986E.mlw
path: /opt/CAPEv2/storage/binaries/3d36bb5638f44641d969a47b93e3e51e85dfeb412e19fc1b0c4441c46c8253dc
crc32: EF017460
md5: 0188c0021b9c2aa5986ea1fcbc5573e9
sha1: e9bfb6b9c7c59b2015ab03b06ee7f0da9328977f
sha256: 3d36bb5638f44641d969a47b93e3e51e85dfeb412e19fc1b0c4441c46c8253dc
sha512: 0628395ea0c0d91bb931de6d1ab9470a4e5a42586ba33ad8fe4e749bf8488ed31ae1fa2e75b072d4b720b53f62ea68ba2d98422cabde4f8a753cb297aea2363e
ssdeep: 24576:BIAnUBTmwHnmG31juOx8DDoZrjj+fNNUP4P/kCjKoi/lh:BIAsTmwGG31JmfoZrIUPU8CeB/v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F045237382662027EAA3B0F36E7A9BE31C71927F04ABDE51D01937D153EE7452D32426
sha3_384: e93d0f95d1c3c9ef935ebc371ed368fd7f17315dc9f96f0d7b1f07472df24dc39620fb9683088118bfeb71ae4d4f67e0
ep_bytes: 60be002051008dbe00f0eeff5783cdff
timestamp: 2019-04-02 15:28:42

Version Info:

Comments:
CompanyName: Satinfo SL.
FileDescription: Utilidad
FileVersion: 2, 14, 4, 14
InternalName: Elis
LegalCopyright: Copyright (C) 2019
LegalTrademarks:
OriginalFilename: Elis.EXE
PrivateBuild:
ProductName: Aplicación Elis
ProductVersion: 2, 14, 4, 14
SpecialBuild:
Translation: 0x0c0a 0x04b0

WebToolbar.Win32.Estapa.heur also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.0188c0021b9c2aa5
CylanceUnsafe
SangforTrojan.Win32.Save.a
CyrenW32/Strictor.P.gen!Eldorado
SymantecTrojan.Zlob
APEXMalicious
ClamAVWin.Malware.Dealply-6997046-0
Kasperskynot-a-virus:HEUR:WebToolbar.Win32.Estapa.heur
SUPERAntiSpywareTrojan.Agent/Generic
AvastFileRepMalware
EmsisoftTrojan.Agent (A)
ComodoTrojWare.Win32.TrojanDownloader.IstBar.~L@f815z
DrWebTrojan.MulDrop9.6156
VIPREVirtumonde.a (fs)
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
SophosBitcoin Miner (PUA)
IkarusTrojan-Downloader.Win32.IstBar
JiangminHeur:TrojanDownloader.Agent
AviraHEUR/AGEN.1119614
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Fakeav.C939114
McAfeeArtemis!0188C0021B9C
VBA32BScope.Trojan.DiskWriter
MalwarebytesTrojan.Agent
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazpZ73Lf+7G/IFRqv2nLtSuW)
YandexTrojan.GenAsa!J1K0INTyvAk
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
BitDefenderThetaGen:NN.ZexaF.34294.mnNfaCKGjXP
AVGFileRepMalware
PandaPUP/PCCleaner

How to remove WebToolbar.Win32.Estapa.heur?

WebToolbar.Win32.Estapa.heur removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment