Malware

Win32/Webprefix.A malicious file

Malware Removal

The Win32/Webprefix.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Webprefix.A virus can do?

  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Webprefix.A?


File Info:

name: 85A28CF0E5FF672EFCE6.mlw
path: /opt/CAPEv2/storage/binaries/0d500986dd8bbdcf7e5e1f62354f35d8db9f18081157f6bf5af0d89d3fb2e7c0
crc32: EF3BFD71
md5: 85a28cf0e5ff672efce6413cf41b3524
sha1: 90a44f4c390e8fe1018252a33f96cc02a24cc7e9
sha256: 0d500986dd8bbdcf7e5e1f62354f35d8db9f18081157f6bf5af0d89d3fb2e7c0
sha512: c61e88c9a5fdf751bb7c1744978b19080f22ab495a5da7f81852dd18c62f9e25d6b1323e898d890c046ca283bd8b44d1051b6049cacf35f95f9138152e866e32
ssdeep: 3072:ByqXwDl5oAhBxnd+Di11mV9EkPNRrFaF97A17cN:+gId+2rQ9EqNRrADlN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FC38C23B4C5C072E02604B58992C6B69A67F878AB311D877BC4566E5F726D3DE3C30B
sha3_384: 7c4cb2a337097f3ac402b7f80ab01aa3e1225ac0563ce435cd5b5b0175ef65f2bed85dd844be351c5ecf074f498cf69b
ep_bytes: e8503b0000e978feffffcc68a0344100
timestamp: 2011-03-13 05:26:46

Version Info:

0: [No Data]

Win32/Webprefix.A also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Poseidon.34
FireEyeGeneric.mg.85a28cf0e5ff672e
CAT-QuickHealTrojan.WebprefixPMF.S27368781
SkyhighBehavesLike.Win32.Generic.ch
ALYacGen:Variant.Poseidon.34
Cylanceunsafe
ZillyaTrojan.Webprefix.Win32.33362
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanDownloader:Win32/Webprefix.afec2da7
K7GWTrojan ( 002317491 )
K7AntiVirusTrojan ( 002317491 )
BitDefenderThetaAI:Packer.413041731F
VirITTrojan.Win32.Generic.BNXU
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Webprefix.A
APEXMalicious
ClamAVWin.Trojan.Agent-36223
KasperskyTrojan-Downloader.Win32.Klevate.z
BitDefenderGen:Variant.Poseidon.34
NANO-AntivirusTrojan.Win32.Webprefix.ddfqwo
AvastWin32:Webprefix [Trj]
TencentTrojan.Win32.Krypttik.a
EmsisoftGen:Variant.Poseidon.34 (B)
BaiduWin32.Trojan.Webprefix.d
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Webprefix.13
VIPREGen:Variant.Poseidon.34
TrendMicroTROJ_AGNT.SMUS28
Trapminemalicious.high.ml.score
SophosTroj/WebPrefi-B
IkarusPacker.Win32.Katusha
GDataWin32.Trojan.PSE.1EM7T06
JiangminPacked.Katusha.abzg
WebrootW32.Trojan.Webprefix
VaristW32/Katusha.F.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Webprefix.a
KingsoftWin32.Troj.Undef.a
XcitiumTrojWare.Win32.Kryptik.KWY@3193xv
ArcabitTrojan.Poseidon.34
ViRobotTrojan.Win32.A.Webprefix.126976
ZoneAlarmTrojan-Downloader.Win32.Klevate.z
MicrosoftTrojan:Win32/Webprefix!pz
CynetMalicious (score: 100)
AhnLab-V3Packed/Win32.Katusha.R3725
McAfeeDownloader-CMM
GoogleDetected
MAXmalware (ai score=100)
VBA32Trojan.Webprefix.01
MalwarebytesWebprefix.Trojan.Dropper.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGNT.SMUS28
RisingTrojan.Win32.Fednu.tfh (CLASSIC)
YandexTrojan.GenAsa!ymfw0RrVZZU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.10565370.susgen
FortinetW32/Katusha.CB!tr
AVGWin32:Webprefix [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Klevate.z

How to remove Win32/Webprefix.A?

Win32/Webprefix.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment