Malware

AdWare.Win32.Wews87.dwk information

Malware Removal

The AdWare.Win32.Wews87.dwk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Wews87.dwk virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Anomalous binary characteristics

Related domains:

a.clickdata.37wan.com

How to determine AdWare.Win32.Wews87.dwk?


File Info:

crc32: D817B315
md5: 1e6c7fada65e2cacb364d230887f42d1
name: dqwhj_wqeq.exe
sha1: 1b16388b2f6ec14676929bcaad1b9b2661df2b61
sha256: d8aa1b78a7f6d2b23fa4583dbaf9d5d37727a770bae4467f7594b34f90dc37e1
sha512: 969c98be9bd35dc160d78b02d103c324c540dd8fb4788d2ca0f32772930fbfd52173b6c2f2ca47600fd9bd5d075177b52951a396779faefecc7da73492c54b76
ssdeep: 24576:xGGMcK+hCmGE8hAV+2T+hh9IZLvXkDdrC+C:xy5OCmM2iIZ4Ds
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: x4e0ax6d77x4e09x4e03x73a9x7f51x7edcx79d1x6280x6709x9650x516cx53f8
FileVersion: 3.0.0.0
CompanyName: x4e0ax6d77x4e09x4e03x73a9x7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: x5927x5929x4f7f2
ProductVersion: 3.0.0.0
FileDescription: x5927x5929x4f7f2 install
Translation: 0x0804 0x03a8

AdWare.Win32.Wews87.dwk also known as:

FireEyeGeneric.mg.1e6c7fada65e2cac
CAT-QuickHealApplication.Agent.ZZ5
McAfeeArtemis!1E6C7FADA65E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaAdWare:Win32/Wews87.3d03b7a0
K7GWAdware ( 004f25fb1 )
K7AntiVirusAdware ( 004f25fb1 )
Invinceaheuristic
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Wews87.B potentially unwanted
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-7331929-0
GDataWin32.Trojan.Agent.D0R8OF
Kasperskynot-a-virus:AdWare.Win32.Wews87.dwk
ViRobotAdware.Wews87.983512
AegisLabAdware.Win32.Wews87.2!c
APEXMalicious
SophosGeneric PUA JL (PUA)
ComodoApplication.Win32.Wews87.E@7mby71
F-SecureAdware.ADWARE/Wews87.udrkk
DrWebProgram.Unwanted.3980
ZillyaAdware.Wews87.Win32.314
McAfee-GW-EditionArtemis!PUP
CyrenW32/Trojan.RVSP-3981
AviraADWARE/Wews87.udrkk
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:AdWare.Win32.Wews87.dwk
MicrosoftPUA:Win32/GameBox
VBA32Adware.Wews
MalwarebytesAdware.ChinAd
RisingPUF.37Wan!1.B87D (CLASSIC)
IkarusAdWare.Wews87
eGambitUnsafe.AI_Score_97%
FortinetRiskware/Wews87
AVGWin32:Malware-gen

How to remove AdWare.Win32.Wews87.dwk?

AdWare.Win32.Wews87.dwk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment