Malware

About “Win32.Etap.Gen.1” infection

Malware Removal

The Win32.Etap.Gen.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Etap.Gen.1 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Executed a sysinternals tool
  • PSExec was executed

How to determine Win32.Etap.Gen.1?


File Info:

name: F083A7926148D19482D4.mlw
path: /opt/CAPEv2/storage/binaries/01fc50a840097061d0b8eaa1f30c1625122b538535a8e16ef019a1071ddc00e2
crc32: 4523E410
md5: f083a7926148d19482d42524fdac767b
sha1: 7e37c41d234178fdcaf61ac072bfbb8c693b5e5f
sha256: 01fc50a840097061d0b8eaa1f30c1625122b538535a8e16ef019a1071ddc00e2
sha512: 222ce53b457942024c62f3c73763539f4688eebb0e775d3b7967eb537315a8132ede43d49beb889fa32a577d8c4e85e55712ee9b4fd5f61b7d08ef3f29d168d3
ssdeep: 6144:7uzb5VGg1c4WVm1WDXzuy116DGuQrCRowf5uFJ:7uz1Vz2h11C+CRowf5uFJ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B464CF2135C3C0B2E01203B09A59D6C64B3FFD577ABDA09FFB9905461BE22D5533A39A
sha3_384: 5a3e9fb1a9f0134b99406b0acf0fe65a98c21c9d52f3bb1e96e19adef536bd93fcca244683123a7a77cb3e4e3bfd2be1
ep_bytes: e87c730000e941feffff565733f6bf00
timestamp: 2007-12-31 14:27:32

Version Info:

CompanyName: Sysinternals - www.sysinternals.com
FileDescription: Execute processes remotely
FileVersion: 1.94
InternalName: PsExec
LegalCopyright: Copyright (C) 2001-2008 Mark Russinovich
OriginalFilename: psexec.c
ProductName: Sysinternals PsExec
ProductVersion: 1.94
Translation: 0x0409 0x04b0

Win32.Etap.Gen.1 also known as:

MicroWorld-eScanWin32.Etap.Gen.1
FireEyeGeneric.mg.f083a7926148d194
CAT-QuickHealW32.Etap
ALYacWin32.Etap.Gen.1
CylanceUnsafe
Cybereasonmalicious.26148d
CyrenW32/Etap
SymantecW32.Simile
Elasticmalicious (high confidence)
ESET-NOD32Win32/Etap
APEXMalicious
KasperskyVirus.Win32.Etap
BitDefenderWin32.Etap.Gen.1
NANO-AntivirusVirus.Win32.Etap.bervfw
AvastWin32:Etap [Inf]
Ad-AwareWin32.Etap.Gen.1
SophosW32/Etap-A
DrWebWin32/Linux.Etap
McAfee-GW-EditionW32/Etap.a.gen
EmsisoftWin32.Etap.Gen.1 (B)
GDataWin32.Etap.Gen.1
AviraW32/Etap
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeW32/Etap.a.gen
MaxSecureVirus.W32.ETap
FortinetW32/ETap.A
BitDefenderThetaAI:FileInfector.254DA71410
AVGWin32:Etap [Inf]
PandaW32/Etap

How to remove Win32.Etap.Gen.1?

Win32.Etap.Gen.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment