removewat 2.2.6.0.rar
The file removewat 2.2.6.0.rar has been detected as a potentially unwanted program by 27 anti-malware scanners. The file has been seen being downloaded from dc315.4shared.com.
File name:
removewat 2.2.6.0.rar
MD5:
c9939efad1708ca79b55fe833fe76892
SHA-1:
392c190c5beac5a5ecdaf8a0bbc10ab1b473b6cd
SHA-256:
885e9cb5bbb0c60be4d9a6aa7fe1bd5f197d22f938a33e7c9b2f0808a5835f39
Scanner detections:
27 / 68
Status:
Potentially unwanted
Analysis date:
11/27/2024 10:49:03 PM UTC (today)
Scan engine
Detection
Engine version
Lavasoft Ad-Aware
Gen:Variant.Application.Kazy.420358
5813612
Arcabit
Trojan.Application.Kazy.D66A06
1.0.0.637
avast!
Win32:Wpakill [PUP]
160111-0
Baidu Antivirus
Hacktool.Win32.WatKill
4.0.3.16112
Bitdefender
Gen:Variant.Application.Kazy.420358
1.0.20.60
Clam AntiVirus
Hacktool.Crack.WPA
0.98/21511
Comodo Security
ApplicUnwnt.Win32.WPAkill.~A
23823
Dr.Web
Tool.Wpakill.7
9.0.1.012
Emsisoft Anti-Malware
Gen:Variant.Application.Kazy.420358
16.01.12
ESET NOD32
MSIL/HackTool.Wpakill.A potentially unsafe application
7.0.302.0
F-Prot
W32/Backdoor2.HKVF (exact, not disinfectable)
4.6.5.141
F-Secure
Gen:Variant.Application.Kazy
11.2016-12-01_3
G Data
Gen:Variant.Application.Kazy.420358
16.1.25
IKARUS anti.virus
HackTool.Win32.Wpakill
t3scan.1.9.5.0
Kaspersky
not-a-virus:RiskTool.Win32.WatKill
15.0.0.562
Malwarebytes
HackTool.WpaKill
v2016.01.12.11
McAfee
Artemis!BFACF78644CA
5600.6523
Microsoft Security Essentials
HackTool:Win32/Wpakill.B
1.1.12400.0
MicroWorld eScan
Gen:Variant.Application.Kazy.420358
17.0.0.36
NANO AntiVirus
Trojan.Win32.Wpakill.dbjivt
1.0.14.5317
Quick Heal
RiskTool.WatKill.g3 (Not a Virus)
1.16.14.00
Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16110
Sophos
PUA 'RemoveWAT' (of type Hacktool)
5.22
Trend Micro House Call
HKTL_WPAKILL
7.2.12
Trend Micro
HKTL_WPAKILL
10.465.12
VIPRE Antivirus
Trojan.Win32.Generic
45948
File size:
6.4 MB (6,666,889 bytes)
Common path:
C:\users\{user}\downloads\removewat 2.2.6.0.rar
The file removewat 2.2.6.0.rar has been seen being distributed by the following URL.