Trojan

Trojan:Win32/Webprefix.C removal tips

Malware Removal

The Trojan:Win32/Webprefix.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Webprefix.C virus can do?

  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
download-web-shield.com

How to determine Trojan:Win32/Webprefix.C?


File Info:

crc32: 0D240780
md5: 6767e1ac18ffbfb6a4f62461ef0eaa86
name: 6767E1AC18FFBFB6A4F62461EF0EAA86.mlw
sha1: 39add6f6c060a3665c55f6e5152039068acc0345
sha256: 5b51f7dbba9b70fbe0a81ab26adbb62a07994eb893571fbf70d8574ee82ff113
sha512: 96527dd8fa3746db7944856e185b86dcc984d83f979ab6483ab0b17404b250111c3fb12ef3a9e40bed41ac01037e16087a8713b8e6f09587717655f872e5772a
ssdeep: 3072:aM65zTN7RH9AvfH3fpp0dL5qxpubZyejITv9fXFg1:1mTNJ0fH3Bp0dLiobP+v9fVa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Webprefix.C also known as:

BkavW32.FamVT.KlevateHQc.Trojan
Elasticmalicious (high confidence)
DrWebBackDoor.Bulknet.1435
MicroWorld-eScanGen:Variant.Dropper.104
FireEyeGeneric.mg.6767e1ac18ffbfb6
McAfeeTrojan-FEHL!6767E1AC18FF
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004d48e41 )
BitDefenderGen:Variant.Dropper.104
K7GWTrojan ( 004d48e41 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.56B258771F
CyrenW32/Occamy.O.gen!Eldorado
SymantecDownloader
APEXMalicious
AvastWin32:FakeAV-FJV [Trj]
ClamAVWin.Trojan.Agent-1365445
KasperskyTrojan-Downloader.Win32.Klevate.j
NANO-AntivirusTrojan.Win32.Bulknet.cwzhzc
ViRobotTrojan.Win32.Downloader.201098
TencentMalware.Win32.Gencirc.10b08916
Ad-AwareGen:Variant.Dropper.104
TACHYONTrojan-Downloader/W32.Klevate.201098
SophosML/PE-A + Troj/WebPrefi-C
ComodoTrojWare.Win32.Webprefix.BG@5jhd9i
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Trojan.Webprefix.a
ZillyaTrojan.Webprefix.Win32.62479
TrendMicroTROJ_WEBPREFIX.SM
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
EmsisoftGen:Variant.Dropper.104 (B)
IkarusAdWare.DProtect
JiangminTrojanDownloader.Klevate.b
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Downloader]/Win32.AGeneric
MicrosoftTrojan:Win32/Webprefix.C
ArcabitTrojan.Dropper.104
SUPERAntiSpywareTrojan.Agent/Gen-Webprefix
ZoneAlarmTrojan-Downloader.Win32.Klevate.j
GDataWin32.Trojan-Dropper.Dlpro.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R94414
Acronissuspicious
VBA32TrojanDownloader.Klevate
MAXmalware (ai score=87)
MalwarebytesMalware.AI.4257706114
PandaTrj/Dtcontx.M
ESET-NOD32a variant of Win32/Webprefix.B
TrendMicro-HouseCallTROJ_WEBPREFIX.SM
RisingTrojan.Klevate!1.A27B (CLASSIC)
SentinelOneStatic AI – Suspicious PE
eGambitTrojan.Generic
FortinetW32/Webprefix.B!tr
Webroot
AVGWin32:FakeAV-FJV [Trj]
Cybereasonmalicious.c18ffb
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Downloader.f2d

How to remove Trojan:Win32/Webprefix.C?

Trojan:Win32/Webprefix.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment