Malware

About “WebToolbar.WhenU” infection

Malware Removal

The WebToolbar.WhenU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WebToolbar.WhenU virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (14 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup

Related domains:

app.whenu.com
www.whenudownloads.com
www.bing.com
www.myplaycity.com
ocsp.globalsign.com
ocsp2.globalsign.com
crl2.alphassl.com
ajax.googleapis.com
cmp.tech426.com
cdn.tech426.com
ocsp.digicert.com
ocsp.pki.goog
www.google-analytics.com
www.googletagservices.com
crl.pki.goog

How to determine WebToolbar.WhenU?


File Info:

crc32: 1A947B68
md5: d42fcffb023d13bcbe62ef777f018701
name: mahjongpsetup.exe
sha1: 11e500f4ae31e5c4d448c788955060aac54b630d
sha256: 64689ce4cddbeb843aa7dd3a6660d0be114d5fee80f72b4e5bda0f6eb4f45fc9
sha512: 0b8a9315d5a432680b0c043c872a69ce6c723638743d730e22eea42413e96b27ec21961bfd0478586433a556f7f5df374eac4f1c0a4a63a7b3c38c69a101e4f5
ssdeep: 98304:edGcJ68iabKg+I4LYEX2fkpPKFXRgCCzlARnfmoxqdTr/8HHoVb1:io3ayfSDgSVfnIHkHmJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2006 MyPlayCity.com
FileDescription: Free Mahjong Planet Setup
FileVersion:
Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: MyPlayCity.com
Translation: 0x0409 0x04e4

WebToolbar.WhenU also known as:

CMCWebToolbar.Win32.WhenU!O
CAT-QuickHealWebToolbar.WhenU
McAfeeArtemis!D42FCFFB023D
BaiduWin32.Trojan.WisdomEyes.16070401.9500.9974
CyrenW32/Tool.VZSS-7523
TrendMicro-HouseCallDialer_Win32Dial
AvastFileRepMetagen [PUP]
Kasperskynot-a-virus:WebToolbar.Win32.WhenU.k
BitDefenderAdware.WhenU.BTE
NANO-AntivirusTrojan.Win32.MLW.ejmft
ViRobotAdware.WhenU.To.5325821
AegisLabWebtoolbar.W32.Whenu!c
RisingTrojan.Generic (cloud:5FV6yuWJ3PE)
F-SecureAdware.WhenU.BTE
DrWebAdware.SaveNow.190
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
EmsisoftAdware.WhenU.BTE (B)
F-ProtW32/HackToolX.AIM
WebrootW32.Malware.Heur
AviraADSPY/AdSpy.Gen
FortinetW32/WhenU
Antiy-AVLRiskWare[WebToolbar]/Win32.WhenU
ArcabitAdware.WhenU.BTE
ZoneAlarmnot-a-virus:WebToolbar.Win32.WhenU.k
MAXmalware (ai score=87)
ESET-NOD32a variant of Win32/Adware.WhenU.SaveNow potentially unwanted
YandexAdware.AdSpy!WJLlep0Vd0g
Ikarusnot-a-virus:AdTool.Win32.WhenU.k
GDataAdware.WhenU.BTE
AVGFileRepMetagen [PUP]
Paloaltogeneric.ml

How to remove WebToolbar.WhenU?

WebToolbar.WhenU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment