Home Malware Programs Adware Adware.WebGet

Adware.WebGet

Posted: May 6, 2014

Threat Metric

Ranking: 3,331
Threat Level: 2/10
Infected PCs: 131,336
First Seen: May 6, 2014
Last Seen: March 9, 2025
OS(es) Affected: Windows


Webget is a potentially unwanted browser extension developed by SuperWeb LLC. Webget may state to improve a PC user's Internet surfing quality by showing website trust rating, related content including websites, allowing discount coupons, comparison shopping and adding other helpful functionalities. Webget is categorized as a potentially unwanted program (PUP) or adware. The browser add-on of Webget may propagate and enter the PC as an extra tool bundled with other freeware. Webget affects Web browsers such as Internet Explorer, Google Chrome, Mozilla Firefox. After installation, Webget may track the computer user's Internet surfing habits by recording various hardware and software information, such as the IP address, search queries entered, unique identifier number, web pages viewed, websites visited, and other similar information. The plug-in of Webget may generate and display various types of intrusive online advertisements including banner, text-link, search, interstitial, transitional, and full page ads possibly with the purpose to gain benefit from advertisement clicks.

Aliases

AdWare.SpadeCast [Ikarus]APPL/BrowseFox.52659 [AntiVir]Artemis!A89D5E65E1D6 [McAfee]Riskware/BrowseFox [Fortinet]Trojan/Win32.TGeneric [Antiy-AVL]Unwanted-Program ( 00454f261 ) [K7AntiVirus]Artemis!3D899F6F3EEB [McAfee]APPL/BrowseFox.sjd.19 [AntiVir]Artemis!CBFFE3CE4175 [McAfee]Generic_r.KF [AVG]AdWare.SwiftBrowse [Ikarus]Trojan/Win32.TSGeneric [Antiy-AVL]Browse Fox [Sophos]Artemis!913166BBE94B [McAfee]Webet [AVG]
More aliases (40)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\webget\updater.bak File name: updater.bak
Size: 109.56 KB (109568 bytes)
MD5: 0178a03e44e9245af8fcc28a73ad479f
Detection count: 1,911
Mime Type: unknown/bak
Path: C:\Program Files (x86)\webget\updater.bak
Group: Malware file
Last Updated: February 5, 2024
system32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}t64.sys File name: {9edd0ea8-2819-47c2-8320-b007d5996f8a}t64.sys
Size: 60.08 KB (60088 bytes)
MD5: 316019fdf9875286eca14816c1104291
Detection count: 57
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: June 13, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{495A5BED-3593-47B5-9B4C-28D17D68572C}{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}{C55F8204-EFF9-4EA1-B541-49253667EB29}{dc264a72-fa75-4948-b881-ea8eff8e5dd2}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\Interface\{F88A773B-C7D6-4097-AD99-144D59C291E1}SOFTWARE\Classes\TypeLib\{0A4AA078-E14F-4459-901A-D5F6ACB22DD6}SOFTWARE\Classes\Wow6432Node\CLSID\{dc264a72-fa75-4948-b881-ea8eff8e5dd2}SOFTWARE\Classes\Wow6432Node\Interface\{F88A773B-C7D6-4097-AD99-144D59C291E1}SOFTWARE\Classes\Wow6432Node\TypeLib\{0A4AA078-E14F-4459-901A-D5F6ACB22DD6}Software\Microsoft\Internet Explorer\Approved Extensions\{14F95421-C981-4820-954E-D83C8537F54C}Software\Microsoft\Internet Explorer\Approved Extensions\{DC264A72-FA75-4948-B881-EA8EFF8E5DD2}SOFTWARE\Microsoft\Tracing\updatewebget_RASAPI32SOFTWARE\Microsoft\Tracing\updatewebget_RASMANCSSOFTWARE\Microsoft\Tracing\utilwebget_RASAPI32SOFTWARE\Microsoft\Tracing\utilwebget_RASMANCSSOFTWARE\Microsoft\Tracing\webget_RASAPI32SOFTWARE\Microsoft\Tracing\webget_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{14F95421-C981-4820-954E-D83C8537F54C}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DC264A72-FA75-4948-B881-EA8EFF8E5DD2}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{14F95421-C981-4820-954E-D83C8537F54C}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DC264A72-FA75-4948-B881-EA8EFF8E5DD2}Software\webgetSOFTWARE\Wow6432Node\Classes\CLSID\{dc264a72-fa75-4948-b881-ea8eff8e5dd2}SOFTWARE\Wow6432Node\Classes\Interface\{F88A773B-C7D6-4097-AD99-144D59C291E1}SOFTWARE\Wow6432Node\Classes\TypeLib\{0A4AA078-E14F-4459-901A-D5F6ACB22DD6}SOFTWARE\Wow6432Node\Microsoft\Tracing\updatewebget_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updatewebget_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilwebget_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilwebget_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\webget_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\webget_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{dc264a72-fa75-4948-b881-ea8eff8e5dd2}SOFTWARE\Wow6432Node\webgetSYSTEM\ControlSet001\services\eventlog\Application\Update webgetSYSTEM\ControlSet001\services\eventlog\Application\Util webgetSYSTEM\ControlSet001\services\Update webgetSYSTEM\ControlSet001\Services\UpdaterSvcWebgetSYSTEM\ControlSet001\Services\Util webgetSYSTEM\ControlSet002\services\eventlog\Application\Update webgetSYSTEM\ControlSet002\services\eventlog\Application\Util webgetSYSTEM\ControlSet002\services\Update webgetSYSTEM\ControlSet002\Services\UpdaterSvcWebgetSYSTEM\ControlSet002\Services\Util webgetSYSTEM\CurrentControlSet\services\eventlog\Application\Update webgetSYSTEM\CurrentControlSet\services\eventlog\Application\Util webgetSYSTEM\CurrentControlSet\services\Update webgetSYSTEM\CurrentControlSet\Services\UpdaterSvcWebgetSYSTEM\CurrentControlSet\Services\Util webgetHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}webget

Additional Information

The following directories were created:
%PROGRAMFILES%\webget%PROGRAMFILES(x86)%\webget%TEMP%\webget
Loading...