ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
W32.Etap-21 found in autoruns.exe
owy


Joined: 13 May 2008
Posts: 0
Location: Australia
Reply with quote
Hello.

My current install of Clamwin (0.93) is making the following noise: C:\Program Files\AutoRuns\autoruns.exe: W32.Etap-21 FOUND.

Not too much when one googles it.

Can anyone shed light on this?

Thanks,

Owen.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Here's some info I found on Sophos (using a Yahoo search):

W32/Etap is a highly complicated cross-platform metamorphic virus which infects
both Windows PE executables and Linux/UNIX ELF format executables.

W32/Etap is a highly complicated cross-platform metamorphic virus which infects
both Windows PE executables and Linux/UNIX ELF format executables.

The virus infects files in all folders and sub-folders on all visible network
drives, with the exception of folders more than 3 levels above the current
folder and folders beginning with the letter 'W' (thus avoiding the Windows
folder).

The virus infects 50% of executables that it finds and does not infect files
with names containing the letter 'V', or beginning with 'PA', 'F-', 'SC', 'DR'
or 'NO'.

When run on the 17th May, or during the months of June, September and December,
the virus may display a message box with the text 'Metaphor 1B By the Mental
Driller/29A'. When run on the 17th May, or during the months of June, September and December,
the virus may display a message box with the text 'Metaphor 1B By the Mental
Driller/29A'. When run on the 14th May and on Hebrew systems,
the virus displays a message box with the text 'Free Palestine!'.

Regards,
View user's profileSend private message
Re: W32.Etap-21 found in autoruns.exe
b0ne


Joined: 26 Oct 2006
Posts: 0
Reply with quote
It is probably a false positive. Update your definitions and see if it is detected again.
View user's profileSend private message
Geekner


Joined: 17 May 2008
Posts: 0
Reply with quote
Confirming this as a false positive. Clamscan found several files from Sysinternals (makers of autoruns) as infected with this virus (accesschk.exe, contig.exe, ect). I downloaded a brand new copy from Sysinternals and compared MD5's, they matched.

Updated definitions and scan no longer finds any virus in those files.
View user's profileSend private message
W32.Etap-21 found in autoruns.exe
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic