Home Possibly Unwanted Program PUP.WebPlayer

PUP.WebPlayer

Posted: July 29, 2013

Threat Metric

Ranking: 8,978
Threat Level: 1/10
Infected PCs: 12,406
First Seen: July 29, 2013
Last Seen: October 8, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\T\Backup Files 2013\00 BACKUP DRIVE FULL CONTENTS 2013\Users\<username>\AppData\Local\WebPlayer\Online Weather\WebPlayer.exe File name: WebPlayer.exe
Size: 196.6 KB (196608 bytes)
MD5: b1eceef0bc142f680dfcbfecb438f929
Detection count: 5,837
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\T\Backup Files 2013\00 BACKUP DRIVE FULL CONTENTS 2013\Users\<username>\AppData\Local\WebPlayer\Online Weather\WebPlayer.exe
Group: Malware file
Last Updated: March 20, 2022
C:\Users\<username>\AppData\Roaming\~ayyhswv.exe File name: ~ayyhswv.exe
Size: 493.27 KB (493272 bytes)
MD5: 87948212c71a773aef4c68029bfae924
Detection count: 410
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\~ayyhswv.exe
Group: Malware file
Last Updated: November 1, 2022

Registry Modifications

The following newly produced Registry Values are:

File name without pathWebplayer Remote.lnkWebplayer.lnkHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\Installer\Features\FEB4726622A4EAA48A16D582355AE726SOFTWARE\Classes\Installer\Products\FEB4726622A4EAA48A16D582355AE726Software\KreapixelSoftware\Kreapixel\WebplayerRemoteSOFTWARE\Microsoft\Tracing\WebplayerRemote_RASAPI32SOFTWARE\Microsoft\Tracing\WebplayerRemote_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\wp_updateSoftware\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webplayer.lnkSoftware\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Webplayer.lnkSOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files (x86)\WebplayerSOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebplayerSOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F750DB0E-D452-3108-63C9-FE16BC686741}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WebplayerSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F750DB0E-D452-3108-63C9-FE16BC686741}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{66274BEF-4A22-4AAE-A861-5D2853A57E62}

Additional Information

The following directories were created:
%APPDATA%\Webplayer%APPDATA%\WebplayerRemote%APPDATA%\wp_update%PROGRAMFILES%\Webplayer%PROGRAMFILES(X86)%\Webplayer%appdata%\Kreapixel
Loading...