Jump to content

WNetWatcher.exe - Wireless Network Watcher v2.31 - False positive


Recommended Posts

Hi, malwarebytes detected today WNetWatcher.exe as a riskware. The exe file is called Wireless Network Watcher by Nirsoft and can be found here: http://www.nirsoft.net/utils/wireless_network_watcher.html

I have the current version v2.31 which I downloaded directly from Nirsoft's website.

Below are the detection results:


-Log Details-
Scan Date: 20/03/2023
Scan Time: 14:23
Log File: c49a439a-c72a-11ed-8d4a-10bf48939f89.json

-Software Information-
Components Version: 1.0.1952
Update Package Version: 1.0.66904
Licence: Premium

-System Information-
OS: Windows 10 (Build 19045.2728)
CPU: x64
File System: NTFS

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 336009
Threats Detected: 3
Threats Quarantined: 0
Time Elapsed: 4 min, 30 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 3
RiskWare.NetworkWatcher, C:\USERS\LAPTOP\APPDATA\ROAMING\Microsoft\Windows\Recent\wnetwatcher.zip.lnk, No Action By User, 16967, 1133333, , , , , 18303BAA22EE3476283238F0408BBD4A, DB15CC04342E7E6364E0A660944826E51D26EF4EA3998EE58C5198E3E6B42434
RiskWare.NetworkWatcher, C:\USERS\LAPTOP\DOWNLOADS\WNETWATCHER.ZIP, No Action By User, 16967, 1133333, 1.0.66904, , ame, , 7BC2103E3EDD1BA5D78FE995817A6FA5, 3EC4F3BC8979E50F55505784E576519A29965FD5BE28244B97D3022F9FCEF4CB
RiskWare.NetworkWatcher, C:\USERS\LAPTOP\PORTABLEAPPS\WNETWATCHER\WNETWATCHER.EXE, No Action By User, 16967, 1133333, 1.0.66904, , ame, , 60E1924798BB2B2F8608E26B37DA5B0B, 564D650EE9C6794B24C5A6497C316B9556F4866263664828EDF4A3CC03F2A8F3

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


Link to post
Share on other sites

2 minutes ago, miekiemoes said:


I will change the detection to PUP.Optional.NetworkWatcher rather, so it becomes a Potentially Unwanted Application. This since this is also used for malicious purposes occasionally. A person who is aware that this is installed would know to create an exclusion for it. 

Alright, this makes sense. Thank you very much for your support.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.