Malware

AdWare.Win32.Wews87.ehl (file analysis)

Malware Removal

The AdWare.Win32.Wews87.ehl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Wews87.ehl virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

a.clickdata.37wan.com

How to determine AdWare.Win32.Wews87.ehl?


File Info:

crc32: EA27B323
md5: cbb880f055b65a318cea42acf604d24f
name: dqwjh_qwe.exe
sha1: ddba4f9eac05ff090de2afa540ea53d0b96dcc64
sha256: 9995d6f3d43f40e531a2c0207b1c0d54612b58c2d97b94169c6aa120b859b27a
sha512: eacea0491a9802f9815d0448c5057511667633bc1691f00c981deac562fa06459490dc66b4c10b8fdb6f232d71e14e4bd5a06313cd12de16df631b2d48e34d06
ssdeep: 24576:Z8QmqJtohK+77EY98O+02/OnyuBQn9rI+uTCQQw6y9gA5aO2gNPfaZ:OQVV+7lJnysQ2qQQw8O7CZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4e09x4e03x4e92x5a31x65d7x4e0bxb7x4e0ax6d77x786cx901ax7f51x7edcx79d1x6280x6709x9650x516cx53f8
FileVersion: 3.0.0.0
CompanyName: x4e09x4e03x4e92x5a31x65d7x4e0bxb7x4e0ax6d77x786cx901ax7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: x4e03x6218
ProductVersion: 3.0.0.0
FileDescription: x4e03x6218 install
Translation: 0x0804 0x03a8

AdWare.Win32.Wews87.ehl also known as:

CAT-QuickHealApplication.Agent.ZZ5
McAfeeArtemis!CBB880F055B6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7GWAdware ( 004fef751 )
K7AntiVirusAdware ( 004fef751 )
Invinceaheuristic
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Wews87.B potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0ECS20
GDataWin32.Application.Agent.P24VVN
Kasperskynot-a-virus:AdWare.Win32.Wews87.ehl
AlibabaAdWare:Win32/Wews87.3dfaeb7c
ViRobotAdware.Wews87.1493168
SophosGeneric PUA CE (PUA)
ComodoApplication.Win32.Wews87.E@7mby71
F-SecureAdware.ADWARE/Wews87.vmqvr
DrWebProgram.Unwanted.3980
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.cbb880f055b65a31
APEXMalicious
CyrenW32/Trojan.YORU-1811
AviraADWARE/Wews87.vmqvr
Antiy-AVLGrayWare/Win32.Puasson
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:AdWare.Win32.Wews87.ehl
MicrosoftTrojan:Win32/Wacatac.C!ml
VBA32BScope.Adware.Wews
MalwarebytesAdware.ChinAd
PandaTrj/CI.A
RisingTrojan.Generic@ML.80 (RDML:WtiqbVkXtG+75QhBHq0RJA)
IkarusAdWare.Wews87
eGambitUnsafe.AI_Score_99%
FortinetAdware/Wews87
AVGFileRepMetagen [Adw]

How to remove AdWare.Win32.Wews87.ehl?

AdWare.Win32.Wews87.ehl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment