We received the file WEBTOUCH.DLL and detected that WEBTOUCH.DLL is not good.
WEBTOUCH.DLL is Adware. You should remove the file WEBTOUCH.DLL.
Kill the process WEBTOUCH.DLL and remove WEBTOUCH.DLL from Windows.
Malware Analysis of WEBTOUCH.DLL
Full path on a computer: %Common Appdata%\WebTouch\WebTouch.dll
Detected by UnHackMe:
WEBTOUCH.DLL
Default location: %Common Appdata%\WebTouch\WebTouch.dll
Removal Results: Success
Number of reboot: 1
WEBTOUCH.DLL is known as:
Adware.WebTouch
WEBTOUCH.DLL hash:
- MD5: aa72f480a733068a205c126a4a9d2eeb
The file tries to connect to the dangerous web site.
How to quickly detect WEBTOUCH.DLL presence?
Registry:
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{80324ef}\UninstallString: “”%SysDir%\RUNDLL32.EXE” “C:\DOCUME~1\ALLUSE~1\APPLIC~1\WebTouch\WebTouch.dll”,_uninstall /un”
- HKLM\System\CurrentControlSet\Services\080324ef\ImagePath: “”%SysDir%\rundll32.exe” “c:\docume~1\alluse~1\applic~1\webtouch\WebTouchSvc.dll”,service”
- HKLM\System\CurrentControlSet\Services\080324ef\DisplayName: “WebTouch”
- HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs: “c:\docume~1\alluse~1\applic~1\webtouch\webtouch.dll”
Folders:
- %Common Appdata%\WebTouch
Files:
- %Temp%\__tmp_2bb30765
- %Common Appdata%\WebTouch\WebTouch.dll
- %Common Appdata%\WebTouch\WebTouchSvc.dll