Malware

Should I remove “Downloader.Win32.WebCompanion.pgh”?

Malware Removal

The Downloader.Win32.WebCompanion.pgh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.WebCompanion.pgh virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Downloader.Win32.WebCompanion.pgh?


File Info:

name: F5B040D232EAF22957EA.mlw
path: /opt/CAPEv2/storage/binaries/df0660746e5e6e723e1632b3d44c02e985fc9bb6d09bc2eb07c69abfa8e310dc
crc32: 606B0714
md5: f5b040d232eaf22957ea32af5ab2bd84
sha1: 5bb3584f142357ea0c26f44cfba932f913646190
sha256: df0660746e5e6e723e1632b3d44c02e985fc9bb6d09bc2eb07c69abfa8e310dc
sha512: be2471054ea29c89f4a8313880525029267f850dcf898d5e427aa2b6a3b9f20445e24023524e5928320539c4285a433fa1789001568295d6cfabf84d74d4dda6
ssdeep: 24576:94nXubIQGyxbPV0db26AzfnlOREnakdEamyqNs8YJi6Ol+lbgUVQHxkkN5K:9qe3f6UqNkeamyv8gO1UVcxkec
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19E85BF3BB268A53EC4AA0B324573D270597B7E61A81A8C1E47F00D0FFF665701E3B656
sha3_384: dec13ffbd7b6c513f2f3071f664be02d071b8832fb62e761aed74bd26ad491437b30c443fbbca095502b80a76aa43db2
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2021-06-03 08:09:11

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Express VPN Setup
FileVersion: 2.0.0.1
LegalCopyright: Express VPN
OriginalFileName:
ProductName: Express VPN
ProductVersion: 2.0
Translation: 0x0000 0x04b0

Downloader.Win32.WebCompanion.pgh also known as:

LionicRiskware.Win32.WebCompanion.1!c
CAT-QuickHealTrojan.Agent
CylanceUnsafe
SangforDownloader.Win32.Agent.Vdhk
K7AntiVirusTrojan ( 0058f3d21 )
AlibabaDownloader:Win32/WebCompanion.1628be1a
K7GWTrojan ( 0058f3d21 )
CyrenW32/Stealer.AI.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.GHT
Paloaltogeneric.ml
ClamAVWin.Dropper.Pasnaino-9938619-0
Kasperskynot-a-virus:Downloader.Win32.WebCompanion.pgh
NANO-AntivirusTrojan.Win32.WebCompanion.jpklfn
AvastFileRepMalware [Misc]
TencentWin32.Trojan-downloader.Agent.Eegu
DrWebTrojan.PWS.Stealer.30446
McAfee-GW-EditionBehavesLike.Win32.DStudio.tc
Trapminemalicious.moderate.ml.score
GDataWin32.Trojan.Agent.KAY1CV
AviraTR/Dldr.Agent.jrtsj
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4956065
McAfeeArtemis!F5B040D232EA
TrendMicro-HouseCallTROJ_GEN.R002H0DFD22
IkarusTrojan-Downloader.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware [Misc]

How to remove Downloader.Win32.WebCompanion.pgh?

Downloader.Win32.WebCompanion.pgh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment