Home Malware Programs Adware Webporpoise

Webporpoise

Posted: April 1, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 1,909
First Seen: April 1, 2014
Last Seen: September 20, 2024
OS(es) Affected: Windows


Webporpoise is an adware program that may be installed from a source on the internet that is questionable. After initiated, Webporpoise ads may be displayed at random where they all try to get users to utilize a coupon deal or online savings offer. Usually clicking on these Webporpoise ads will redirect you to unwanted or questionable sites. Removing the Webporpoise ads may necessitate finding and deleting all files related to Webporpoise using an antimalware application.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\webporpoise\updater.exe File name: updater.exe
Size: 109.56 KB (109568 bytes)
MD5: 65a9e6881c6c017446a51c543fd91ab9
Detection count: 129
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\webporpoise
Group: Malware file
Last Updated: July 2, 2014
%PROGRAMFILES%\webporpoise\updatewebporpoise.exe File name: updatewebporpoise.exe
Size: 317.72 KB (317728 bytes)
MD5: 6445624ea427618dbc1fbce16808b932
Detection count: 129
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\webporpoise
Group: Malware file
Last Updated: July 2, 2014
%PROGRAMFILES(x86)%\webporpoise\bin\webporpoise.BrowserAdapter.exe File name: webporpoise.BrowserAdapter.exe
Size: 95.52 KB (95520 bytes)
MD5: 022a5577b35a20480d30acd56de3d06c
Detection count: 77
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\webporpoise\bin
Group: Malware file
Last Updated: July 2, 2014
%PROGRAMFILES(x86)%\webporpoise\bin\FilterApp_C64.exe File name: FilterApp_C64.exe
Size: 287 KB (287008 bytes)
MD5: cc2c7fd040937f8ccb96212a1a5c0dc9
Detection count: 76
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\webporpoise\bin
Group: Malware file
Last Updated: July 2, 2014
%PROGRAMFILES%\webporpoise\bin\utilwebporpoise.exe File name: utilwebporpoise.exe
Size: 317.72 KB (317728 bytes)
MD5: b97229638ab237f921ba3c6f3f8d2e44
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\webporpoise\bin
Group: Malware file
Last Updated: July 2, 2014
system32\drivers\{572f484b-455f-44b0-9d6a-da3ad2071365}t64.sys File name: {572f484b-455f-44b0-9d6a-da3ad2071365}t64.sys
Size: 60.09 KB (60096 bytes)
MD5: 0cf92dfaa3bedd88756a7c87d3f9bdd6
Detection count: 30
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 2, 2014
%PROGRAMFILES%\webporpoise\bin\FilterApp_C.exe File name: FilterApp_C.exe
Size: 238.88 KB (238880 bytes)
MD5: a2b8e350a5158da61e6de039bf84e709
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\webporpoise\bin
Group: Malware file
Last Updated: July 2, 2014
%PROGRAMFILES%\webporpoise\webporpoise.FirstRun.exe File name: webporpoise.FirstRun.exe
Size: 1.12 MB (1122592 bytes)
MD5: 557265750defe4cb928c773f0c35a26e
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\webporpoise
Group: Malware file
Last Updated: July 2, 2014
%PROGRAMFILES%\webporpoise\bin\webporpoise.PurBrowse.exe File name: webporpoise.PurBrowse.exe
Size: 239.39 KB (239392 bytes)
MD5: 6582e62d0d36e2f3242c58063d13171e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\webporpoise\bin
Group: Malware file
Last Updated: July 2, 2014
%PROGRAMFILES(x86)%\webporpoise\webporpoiseuninstall.exe File name: webporpoiseuninstall.exe
Size: 241.55 KB (241556 bytes)
MD5: 0cce6880209e955c916342c894d6e771
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\webporpoise
Group: Malware file
Last Updated: July 2, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{4CCA3E1F-DA3A-4C17-B0A4-1D931B6BFB93}{f31845e6-7a36-476e-802e-f81e59588e80}{F9A52E7F-ABFB-4C8A-902B-A157F0ADF518}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{F31845E6-7A36-476E-802E-F81E59588E80}Software\Microsoft\Internet Explorer\DOMStorage\webporpoise.bizSOFTWARE\Microsoft\Tracing\updatewebporpoise_RASAPI32SOFTWARE\Microsoft\Tracing\updatewebporpoise_RASMANCSSOFTWARE\Microsoft\Tracing\webporpoise_RASAPI32SOFTWARE\Microsoft\Tracing\webporpoise_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{F31845E6-7A36-476E-802E-F81E59588E80}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F31845E6-7A36-476E-802E-F81E59588E80}Software\webporpoiseSOFTWARE\Wow6432Node\Microsoft\Tracing\updatewebporpoise_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updatewebporpoise_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\webporpoise_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\webporpoise_RASMANCSSOFTWARE\Wow6432Node\webporpoiseSYSTEM\ControlSet001\services\eventlog\Application\Update webporpoiseSYSTEM\ControlSet001\services\eventlog\Application\Util webporpoiseSYSTEM\ControlSet001\services\Update webporpoiseSYSTEM\ControlSet002\services\eventlog\Application\Update webporpoiseSYSTEM\ControlSet002\services\eventlog\Application\Util webporpoiseSYSTEM\ControlSet002\services\Update webporpoiseSYSTEM\CurrentControlSet\services\eventlog\Application\Update webporpoiseSYSTEM\CurrentControlSet\services\eventlog\Application\Util webporpoiseSYSTEM\CurrentControlSet\services\Update webporpoiseHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}webporpoise

Additional Information

The following directories were created:
%PROGRAMFILES%\webporpoise%PROGRAMFILES(x86)%\webporpoise
The following URL's were detected:
webporpoise
Loading...