Malware

Rogue:Win32/Winwebsec!pz (file analysis)

Malware Removal

The Rogue:Win32/Winwebsec!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rogue:Win32/Winwebsec!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself

How to determine Rogue:Win32/Winwebsec!pz?


File Info:

name: 292604F404E90962F538.mlw
path: /opt/CAPEv2/storage/binaries/cb1d571654035bce8cd2a47802dd6425216eef138366b9a6101e5983b3fd84cd
crc32: D6C95828
md5: 292604f404e90962f538ba9989a2a596
sha1: 248602e634c1760301d9492d42d0aeaa4b17c7f7
sha256: cb1d571654035bce8cd2a47802dd6425216eef138366b9a6101e5983b3fd84cd
sha512: 4304fc1233ba7c7dcee7c000dc0b34cf684f674e2a06dd48c32e2a7ef568bca51e98df4135bc87c0838d59f347a0a3a50508ec830ebcbdc6e2cf1fdbcde1674d
ssdeep: 384:dxORUlNbEFCYn2UUGcNeLNek+vDMDc58XttLmdOOM2R7GykwAXlu/Tnm8LAp9:dxdNQFzRA5MtVmd5MRwYu7n/Mp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1943329E27225C980E7148E3D99F34E58E628FC33792D2905F3D44D2F6E37A89982255E
sha3_384: de2bbe5eba3c608a93e09c9d5872d68d14511ca4d4d9425933c793a35deec09f16a1f3de298c8b51142c3000372eaf17
ep_bytes: 6a00e8c1feffff6a026a006850604000
timestamp: 2011-10-25 19:34:24

Version Info:

0: [No Data]

Rogue:Win32/Winwebsec!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lmka
AVGWin32:Kryptik-GLK [Trj]
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.295426
FireEyeGeneric.mg.292604f404e90962
CAT-QuickHealTrojan.Lethic.B
SkyhighBehavesLike.Win32.Backdoor.qz
McAfeeGeneric FakeAV.nz
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.FakeAV.Win32.177156
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirTool:Win32/Obfuscator.bb36a354
K7GWTrojan ( 0048bace1 )
K7AntiVirusTrojan ( 0048bace1 )
BitDefenderThetaGen:NN.ZexaF.36802.dqZ@am6dwEii
VirITTrojan.Win32.Generic.BUUK
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.YUD
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Kryptik-GLK [Trj]
ClamAVWin.Trojan.Fakeav-8973
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.295426
NANO-AntivirusTrojan.Win32.Tenagour.bbmjsf
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
TencentMalware.Win32.Gencirc.10b1da8c
EmsisoftGen:Variant.Razy.295426 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen5
DrWebTrojan.Tenagour.9
VIPREGen:Variant.Razy.295426
TrendMicroTROJ_KRYPTK.SMJY
Trapminemalicious.moderate.ml.score
SophosMal/EncPk-ACU
IkarusDDoS.Win32.Dofoil
JiangminTrojan/Fakeav.aoto
WebrootW32.Rogue.Gen
VaristW32/FakeAlert.TU.gen!Eldorado
AviraTR/Crypt.XPACK.Gen5
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Unknown
Kingsoftmalware.kb.a.1000
MicrosoftRogue:Win32/Winwebsec!pz
XcitiumTrojWare.Win32.Kryptik.YWM@4marxh
ArcabitTrojan.Razy.D48202
ViRobotTrojan.Win32.A.FakeAV.52736
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.295426
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R17117
VBA32Trojan.FakeAV.01657
ALYacGen:Variant.Razy.295426
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SMJY
RisingDownloader.Dofoil!8.322 (TFE:5:MKX2RKV5EB)
YandexTrojan.GenAsa!v366MDTy700
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Kryptik.MUH!tr
Cybereasonmalicious.404e90
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Razy

How to remove Rogue:Win32/Winwebsec!pz?

Rogue:Win32/Winwebsec!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment