Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

WEBTOUCHSVC.DLL is Adware WebTouch

$
0
0

We received the file WEBTOUCHSVC.DLL and detected that WEBTOUCHSVC.DLL is not good.
WEBTOUCHSVC.DLL is Adware. You should remove the file WEBTOUCHSVC.DLL.
Kill the process WEBTOUCHSVC.DLL and remove WEBTOUCHSVC.DLL from Windows.

Malware Analysis of WEBTOUCHSVC.DLL
Full path on a computer: %Common Appdata%\WebTouch\WebTouchSvc.dll

Detected by UnHackMe:

WEBTOUCHSVC.DLL
Default location: %Common Appdata%\WebTouch\WebTouchSvc.dll

Removal Results: Success
Number of reboot: 1

WEBTOUCHSVC.DLL is known as:

Adware.WebTouch

WEBTOUCHSVC.DLL hash:

  • MD5: 14e259d78b011c3eeffbd3a63da4f31d
The file tries to download information from some web sites.
How to quickly detect WEBTOUCHSVC.DLL presence?
Registry:
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{80324ef}\UninstallString: “”%SysDir%\RUNDLL32.EXE” “C:\DOCUME~1\ALLUSE~1\APPLIC~1\WebTouch\WebTouch.dll”,_uninstall /un”
  • HKLM\System\CurrentControlSet\Services\080324ef\ImagePath: “”%SysDir%\rundll32.exe” “c:\docume~1\alluse~1\applic~1\webtouch\WebTouchSvc.dll”,service”
  • HKLM\System\CurrentControlSet\Services\080324ef\DisplayName: “WebTouch”
  • HKLM\System\CurrentControlSet\Services\080324ef\ObjectName: “LocalSystem”
  • HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs: “c:\docume~1\alluse~1\applic~1\webtouch\webtouch.dll”
Folders:
  • %Common Appdata%\WebTouch
Files:
  • %Temp%\__tmp_2bb30765
  • %Common Appdata%\WebTouch\WebTouch.dll
  • %Common Appdata%\WebTouch\WebTouchSvc.dll


Viewing all articles
Browse latest Browse all 38585

Trending Articles