Malware

About “Rogue:Win32/Winwebsec!pz” infection

Malware Removal

The Rogue:Win32/Winwebsec!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rogue:Win32/Winwebsec!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Rogue:Win32/Winwebsec!pz?


File Info:

name: 86A9C24A234908126176.mlw
path: /opt/CAPEv2/storage/binaries/11961da596813052547b5baaf5c94249ceb3df8d60d535b7deae227c435eb159
crc32: 2BAA6F05
md5: 86a9c24a23490812617623849287ee8f
sha1: 7af5cb0748f892fe14e5457f4cfbce658644ec88
sha256: 11961da596813052547b5baaf5c94249ceb3df8d60d535b7deae227c435eb159
sha512: d1b541d3b0c0d2a588ff62add204bb36604864d6eb93918f83e1f7a327444b38793fc8cf0e55b75b1aded0361494fb516023215e30b001e1b4a7028186f3f89d
ssdeep: 6144:1l4LDypt7vcsZf3hiQEufdHAzFB0sKm8HJ8B2bipuJBDKMa9o+S89SBGQIqp/Tgc:zSDi1csZ5iQjOFBEYcJa9oxz9/U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1129412CBBCEAD3D0E23F8F7D4E076D9C021665CB2754AF1EE62B7B212362C891594194
sha3_384: 99613db261870d2d152bcf1777dbdf82ceaacf517a574ad6b180b8d3fc3ab63611178c2301c8f02434d6908a5af5cd06
ep_bytes: 558bec81c4dcfaffff5668000100008d
timestamp: 2005-07-25 17:38:49

Version Info:

0: [No Data]

Rogue:Win32/Winwebsec!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FakeAV.lo0k
Elasticmalicious (high confidence)
DrWebTrojan.Fakealert.20359
MicroWorld-eScanGen:Trojan.Heur.KS.4
ClamAVWin.Trojan.Diple-6
FireEyeGeneric.mg.86a9c24a23490812
CAT-QuickHealFraudTool.Security
SkyhighBehavesLike.Win32.Generic.gc
ALYacGen:Trojan.Heur.KS.4
Cylanceunsafe
ZillyaTrojan.FakeAV.Win32.50909
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 002255a81 )
AlibabaMalware:Win32/km_2431.None
K7GWTrojan ( 002255a81 )
Cybereasonmalicious.748f89
ArcabitTrojan.Heur.KS.4
BitDefenderThetaAI:Packer.4B68629A14
VirITFraudTool.SystemTool.B
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.LMA
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Diple.ilq
BitDefenderGen:Trojan.Heur.KS.4
NANO-AntivirusTrojan.Win32.Diple.cekwe
ViRobotTrojan.Win32.A.Diple.410378
AvastWin32:Cycbot-BP [Trj]
TencentMalware.Win32.Gencirc.114d35f0
TACHYONTrojan/W32.Diple.412160
EmsisoftGen:Trojan.Heur.KS.4 (B)
F-SecureTrojan.TR/FakeAV.btxt.8
VIPREGen:Trojan.Heur.KS.4
TrendMicroTROJ_FAKEAV.SMID
Trapminemalicious.high.ml.score
SophosMal/FakeAV-IS
IkarusTrojan.Win32.FakeAV
JiangminTrojan/Diple.zl
WebrootW32.Rogue.Winwebsec
GoogleDetected
AviraTR/FakeAV.btxt.8
Antiy-AVLTrojan/Win32.Diple
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.LML@2v8xjn
MicrosoftRogue:Win32/Winwebsec!pz
SUPERAntiSpywareTrojan.Agent/Gen-FakeSecurity
ZoneAlarmTrojan.Win32.Diple.ilq
GDataGen:Trojan.Heur.KS.4
VaristW32/FakeAlert.JW.gen!Eldorado
AhnLab-V3Trojan/Win32.FakeAV.R2866
McAfeeGeneric FakeAV.oi
MAXmalware (ai score=100)
VBA32SScope.Malware-Cryptor.Maxplus.0997
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Cycbot.gen
TrendMicro-HouseCallTROJ_FAKEAV.SMID
RisingTrojan.FakeAV!1.658F (CLASSIC)
YandexTrojan.GenAsa!QhhnZ7m6n6c
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.FakeAV.Bczm
FortinetW32/FraudPack.CG!tr
AVGWin32:Cycbot-BP [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Rogue:Win32/Winwebsec!pz?

Rogue:Win32/Winwebsec!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment