Malware

AdWare.Win32.Wews87.cwb (file analysis)

Malware Removal

The AdWare.Win32.Wews87.cwb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Wews87.cwb virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
a.clickdata.37wan.com

How to determine AdWare.Win32.Wews87.cwb?


File Info:

crc32: FBA35568
md5: 4b18a5f6e5062c9657edecd008258932
name: dwqh_weqee.exe
sha1: 40249b0d5b974c054ff38cd6d3b089e73bddb8a9
sha256: 5754fec4060c245b76f6c7eed72c780fad351a78b1834e9a8557d9ce1c2b118c
sha512: 58763ab284b2509c3cf85d4c2c97c173443369f654772fe5793df801e1adf64107848fd1af4bbba272f4fd133dbb6824720ae067c493d8ffeb0b65190c7b1d18
ssdeep: 24576:jpbeBYcIVW7LZKA2IHy5MajeHc81Sm94B2nroZESB:jpRe7cAe5SHc81VmOQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4e0ax6d77x4e09x4e03x73a9x7f51x7edcx79d1x6280x6709x9650x516cx53f8
FileVersion: 3.0.0.0
CompanyName: x4e0ax6d77x4e09x4e03x73a9x7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: x731bx5c06x5929x4e0b
ProductVersion: 3.0.0.0
FileDescription: x731bx5c06x5929x4e0b install
Translation: 0x0804 0x03a8

AdWare.Win32.Wews87.cwb also known as:

FireEyeGeneric.mg.4b18a5f6e5062c96
CAT-QuickHealApplication.Agent.ZZ5
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabAdware.Win32.Wews87.2!c
K7AntiVirusAdware ( 004fef751 )
K7GWAdware ( 004fef751 )
Invinceaheuristic
APEXMalicious
Kasperskynot-a-virus:AdWare.Win32.Wews87.cwb
AlibabaAdWare:Win32/Wews87.4e9569fb
NANO-AntivirusRiskware.Win32.Wews87.fsgrex
RisingTrojan.Generic@ML.90 (RDMK:t+UrE5A+dbRAr7FNil5Kug)
ComodoMalware@#us211u01pgzk
F-SecureAdware.ADWARE/Wews87.bdmlx
DrWebProgram.Unwanted.3980
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA EE (PUA)
IkarusAdWare.Wews87
AviraADWARE/Wews87.bdmlx
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:AdWare.Win32.Wews87.cwb
MicrosoftPUA:Win32/GameBox
AhnLab-V3Malware/Gen.Generic.C2850571
McAfeeArtemis!4B18A5F6E506
VBA32BScope.Adware.Wews
MalwarebytesAdware.ChinAd
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Wews87.B potentially unwanted
TencentWin32.Adware.Wews87.Pciy
eGambitUnsafe.AI_Score_99%
FortinetRiskware/Wews87
AVGWin32:AdwareSig [Adw]
AvastWin32:AdwareSig [Adw]
Qihoo-360Win32/Trojan.Adware.37e

How to remove AdWare.Win32.Wews87.cwb?

AdWare.Win32.Wews87.cwb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment