Malware

What is “Rogue:Win32/Winwebsec!pz”?

Malware Removal

The Rogue:Win32/Winwebsec!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rogue:Win32/Winwebsec!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Rogue:Win32/Winwebsec!pz?


File Info:

name: D9E7B0EBBBE50C9A8C1E.mlw
path: /opt/CAPEv2/storage/binaries/d2239cc380388102f1cad3411436bee673f381f8846a8c041f44b1bf6d231dfc
crc32: DEC3EAF4
md5: d9e7b0ebbbe50c9a8c1e33108833acee
sha1: 826a5124a2c86214bb16a420ece795662c8d4944
sha256: d2239cc380388102f1cad3411436bee673f381f8846a8c041f44b1bf6d231dfc
sha512: b54a8ddf079f0f9c1d4838755ca0b7b446164aeacbc8f6dee11ac9670b60dfb63e6ec024f1753c4a6cef97ba16fd5f6b7b4b94b8b8762bada525111740d0e075
ssdeep: 6144:Lf3ipYZsiZh1H9oFVFvJYVQl4HogAiKJ7/C6JHfrzczOAA0n7aESBxI3DsFFy7cb:TipYHh1H9o++9nzJ766JHfr2rSkIFFtB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B840104C300EBCBDBCC77F5A81576E401169C15C0BE9BE6A682BECFBA736291532A15
sha3_384: 735ab7daef96bf9576585e1168a9c36ae0eb375adba65c1cb284d7772b320f9af2d2663ca3543a43ef3660b0a96552be
ep_bytes: 558bec81c4dcfaffff566a208d742450
timestamp: 1970-03-09 11:21:04

Version Info:

0: [No Data]

Rogue:Win32/Winwebsec!pz also known as:

BkavW32.RansomQKC.Fam.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Cridex.2
FireEyeGeneric.mg.d9e7b0ebbbe50c9a
CAT-QuickHealFraudTool.Security
SkyhighBehavesLike.Win32.SuspiciousFake.fc
Cylanceunsafe
ZillyaTrojan.FakeAV.Win32.55002
SangforSuspicious.Win32.Save.a
AlibabaVirTool:Win32/Obfuscator.d79cb13e
K7GWHacktool ( 700007861 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36680.wqW@aGdkpBpi
VirITTrojan.Win32.Zyx.X
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Adware.SystemSecurity.AG
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-314075
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Cridex.2
NANO-AntivirusTrojan.Win32.Kryptik.bzxds
SUPERAntiSpywareTrojan.Agent/Gen-FakeSecurity
AvastWin32:FakeAV-BLY [Trj]
TencentMalware.Win32.Gencirc.10b2ea59
EmsisoftGen:Heur.Cridex.2 (B)
F-SecureTrojan.TR/Kazy.17917.26
DrWebTrojan.Fakealert.20577
VIPREGen:Heur.Cridex.2
TrendMicroTROJ_FAKEAV.SMID
SophosMal/FakeAV-IS
IkarusTrojan.Win32.FakeAV
JiangminTrojan/Fakeav.ouk
WebrootW32.Rogue.Winwebsec
VaristW32/FakeAlert.LY.gen!Eldorado
AviraTR/Kazy.17917.26
Antiy-AVLTrojan/Win32.FakeAV
KingsoftWin32.NotVirus.FlashApp.a
MicrosoftRogue:Win32/Winwebsec!pz
XcitiumTrojWare.Win32.FakeAV.BT@338rhv
ArcabitTrojan.Cridex.2
ViRobotTrojan.Win32.FakeAV.375808
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Cridex.2
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R3897
Acronissuspicious
McAfeeGeneric FakeAV.oi
MAXmalware (ai score=100)
VBA32BScope.Trojan.FakeAV
MalwarebytesMalware.AI.210595824
PandaAdware/WinWebSecurity2008
TrendMicro-HouseCallTROJ_FAKEAV.SMID
RisingTrojan.FakeAV!1.658F (CLASSIC)
YandexTrojan.GenAsa!jKJbyZdC+is
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FakeAlert.AMB!tr
AVGWin32:FakeAV-BLY [Trj]
Cybereasonmalicious.4a2c86
DeepInstinctMALICIOUS

How to remove Rogue:Win32/Winwebsec!pz?

Rogue:Win32/Winwebsec!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment