PUA

PUA:Win32/WebWatcher removal tips

Malware Removal

The PUA:Win32/WebWatcher is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/WebWatcher virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid

How to determine PUA:Win32/WebWatcher?


File Info:

name: 86EA12D1B9A4BC418FC8.mlw
path: /opt/CAPEv2/storage/binaries/c2de93209da0de8a4bfa847eab573072e2dca133c1975ea536bb44d10260bb81
crc32: 7C64AD9E
md5: 86ea12d1b9a4bc418fc8e901b9a3935f
sha1: 6d8473c24934eafa84b1eb85afcf54cb98b73a7c
sha256: c2de93209da0de8a4bfa847eab573072e2dca133c1975ea536bb44d10260bb81
sha512: f674cf9a8e96cf856b1ec5fc1fead21eef73d64c23b616aeda83c9bdabb881066659a060e9aee8e012573984fe7c03f112119ab005df9461585736aa342c6caf
ssdeep: 3072:5qCc8qKmjWZ1apGcCq+MI1zqlFydi+1hhEcgBDV7Bl2wz/uNF+K2:5qJNKiK1apGcCqHueKg1V2Iuej
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T17344AE603996C537EA8F0131D5FB8B6F197EA5222B65C4CFF3980E896E701C32A35653
sha3_384: b47f9b6c6bd902d0e1fe7a3c759b65b07cb71605f7b62532753bb0b7e3fad667905f8509a1e1607feb367c25ee74af58
ep_bytes: 837c2408017505e8e06f0000ff742404
timestamp: 2022-08-23 20:17:05

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 8, 2, 62, 1220
InternalName:
LegalCopyright:
LegalTrademarks:
OLESelfRegister:
OriginalFilename:
PrivateBuild:
ProductName:
ProductVersion: 8, 2, 62, 1220
SpecialBuild:
Translation: 0x0409 0x04b0

PUA:Win32/WebWatcher also known as:

LionicTrojan.Win32.Monitor.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Keylogger.WebWatcher.51
ClamAVWin.Keylogger.Webwatcher-9787066-0
ALYacGen:Variant.Application.Keylogger.WebWatcher.51
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056c6451 )
AlibabaMonitor:Win32/WebWatcher.e94a8b43
K7GWTrojan ( 0056c6451 )
CrowdStrikewin/grayware_confidence_100% (W)
VirITPUP.Win32.AwareTech.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Monitor.WebWatcher.F
CynetMalicious (score: 99)
BitDefenderGen:Variant.Application.Keylogger.WebWatcher.51
ViRobotAdware.Webwatcher.259208
AvastWin32:Malware-gen
RisingHackTool.WebWatcher!8.13490 (TFE:5:Br2ONqiwIAE)
EmsisoftApplication.WebMonitor (A)
F-SecureProgram.APPL/MonitorTool.Gen
DrWebTrojan.Siggen7.26542
VIPREGen:Variant.Application.Keylogger.WebWatcher.51
TrendMicroPUA.Win32.WebWatcher.K
FireEyeGeneric.mg.86ea12d1b9a4bc41
SophosWebWatcher (PUA)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.Skillis.B
JiangminMonitor.WebWatcher.iu
WebrootW32.Systemmonitor.Webwatcher
GoogleDetected
AviraAPPL/MonitorTool.Gen
XcitiumApplicUnwnt@#afqr4i76iutp
ArcabitTrojan.Application.Keylogger.WebWatcher.51
SUPERAntiSpywarePUP.WebWatcher/Variant
MicrosoftPUA:Win32/WebWatcher
VaristW32/Trojan.HIU.gen!Eldorado
AhnLab-V3Malware/Win.Generic.R512582
McAfeeArtemis!86EA12D1B9A4
MAXmalware (ai score=74)
VBA32Adware.WebWatcher
MalwarebytesWebWatcher.Spyware.Monitor.DDS
TrendMicro-HouseCallPUA.Win32.WebWatcher.K
IkarusTrojan.Win32.Skillis
MaxSecurenot-a-virus:Monitor.WebWatcher.gen
FortinetRiskware/WebWatcher
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove PUA:Win32/WebWatcher?

PUA:Win32/WebWatcher removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment