wat_remover_by_digipassion.com.exe

RemoveWAT

Hazar & Co.

The application wat_remover_by_digipassion.com.exe has been detected as a potentially unwanted program by 31 anti-malware scanners. This is a setup program which is used to install the application. This file is typically installed with the program Activador Server Extremo 2008 R2 by LANDERX.
Publisher:
Hazar & Co.

Product:
RemoveWAT

Version:
2.2.5.2

MD5:
588c9f669bfb9149c4f1d8e6729743ba

SHA-1:
75e0288583dd3301386b12de8f8c27eebdbdfc7a

SHA-256:
46da5058c5bc04b520298337cd2614e3f27c6444222b04feefe7b3e7cb68ff83

Scanner detections:
31 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 12:30:35 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Hacktool.RemoveWAT.A
1129

Agnitum Outpost
HackTool.Wpakill
7.1.1

AhnLab V3 Security
PUP/Win32.101Alemi
2013.12.20

Avira AntiVirus
SPR/Tool.WPAkill.B.7
7.11.121.110

avast!
Win32:PUP-gen [PUP]
2014.9-140102

AVG
HackTool
2015.0.3607

Bitdefender
Application.Hacktool.RemoveWAT.A
1.0.20.10

Bkav FE
W32.Clodf97.Trojan
1.3.0.4613

Clam AntiVirus
Hacktool.Crack.WPA
0.98/18355

Comodo Security
ApplicUnwnt.Win32.WPAkill.~A
17469

Dr.Web
Tool.Siggen.6228
9.0.1.02

Emsisoft Anti-Malware
Trojan.GenericKD.1397145
8.13.12.25.12

Fortinet FortiGate
Riskware/RemoveWAT
12/25/2013

F-Prot
W32/MalwareF.GUGF
v6.4.7.1.166

F-Secure
Application.Hacktool.RemoveWAT
11.2014-02-01_5

G Data
Application.Hacktool.RemoveWAT
14.1.22

IKARUS anti.virus
HackTool.Win32.Wpakill
t3scan.2.2.29

K7 AntiVirus
Riskware
13.174.10623

Kaspersky
not-a-virus:RiskTool.Win32.WatKill
14.0.0.4528

Malwarebytes
HackTool.Wpakill
v2013.12.25.12

McAfee
Artemis!347C23328DF3
5600.7271

Microsoft Security Essentials
HackTool:Win32/Wpakill.B
1.165.247.01

MicroWorld eScan
Application.Hacktool.RemoveWAT.A
15.0.0.6

Norman
Suspicious_Gen2.KFAML
11.20140102

Rising Antivirus
PE:Trojan.Win32.Generic.124713F0!306648048
23.00.65.131223

Sophos
RemoveWAT
4.96

SUPERAntiSpyware
Hacktool.WPAKill
10870

Trend Micro House Call
HKTL_WPAKILL
7.2.359

Trend Micro
HKTL_WPAKILL
10.465.25

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
24664

ViRobot
JS.A.Iframe.6663680
2011.4.7.4223

File size:
6.4 MB (6,663,680 bytes)

Product version:
2.2.5.2

Copyright:
Copyright Hazar & Co. © 2010

Original file name:
RemoveWAT.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\wat_remover_by_digipassion.com.exe

File PE Metadata
Compilation timestamp:
3/2/2010 4:57:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:/33yKMaL/eXV1i/kDxkmcL/eXV1i/kaRWYL/eXV1i/kmeM1qj4iwiANvSo2/CAy1:vyKnZrrLGA3PhsKPkG09Wp

Entry address:
0x64359E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 52, 35, 8D, 4B, 00, 00, 00, 00, 02, 00, 00, 00, 3D, 00, 00, 00, 1C, 40, 64, 00, 1C, 1A, 64, 00, 52, 53...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
6.3 MB (6,559,232 bytes)

The file wat_remover_by_digipassion.com.exe has been discovered within the following program.

www.landerextremo.s5.com
About 3% of users remove it
 
Powered by Should I Remove It?

The file wat_remover_by_digipassion.com.exe has been seen being distributed by the following 31 URLs.

ftp://10.120.42.8/Progarm/crack window 7 kone/.../RemoveWAT22/RemoveWAT.exe

http://download1065.mediafire.com/m7hzg6i3bpog/.../RemoveWAT.exe

https://dl-web.dropbox.com/get/.../Rem225.exe

temp:Remove v2.2.5.exe

http://dc731.4shared.com/download/.../removewat_227.exe

https://doc-0k-74-docs.googleusercontent.com/docs/securesc/9qa0linngihp75k4b0rqt3i5pbq6v0tf/k7k8sq0nvele5lfas9lk4hjgqiiu3dgu/1470513600000/.../05878226080220982185/0BzoTSOsm5rPQdlhCVGdsQk1aWk0?e=download

ftp://172.21.1.40/3. Aplikasi_Intaller/Crack Windows All/Genuine_7/.../RemoveWAT_2.exe

about:internet

http://199.91.153.41/r95do5hp9olg/.../RemoveWAT.exe

Latest 30 of 31 download URLs

Remove wat_remover_by_digipassion.com.exe - Powered by Reason Core Security