How to Remove “Drwtsn32.exe”

What is Drwtsn32.exe?

Drwtsn32.exe is a legitimate process file popularly known as DrWatson Postmortem Debugger. It is associated with Windows Operating System, developed by Microsoft Corporation. It is located in C:\Windows\System32 by default. Malware programmers create files with virus scripts and name them after Drwtsn32.exe  with an intention to spread virus on the internet.

Affected Platform: Windows OS

How to check if your computer is infected with Drwtsn32.exe malware?

Keep an eye for the following symptoms to see if your PC is infected with Drwtsn32.exe malware:

  • Internet connection fluctuates
  • Drwtsn32.exe  takes too much CPU space
  • PC slows down significantly
  • Browser automatically redirects to some irrelevant websites
  • Unsolicited ads and popups starts appearing
  • Screen freezes constantly

Take the following steps to diagnose your PC for possible Drwtsn32.exe malware attack:

Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.

Step 2: If you notice the file located outside C:\Windows\System32, then you should run an antivirus scan to get rid of the malware.

How to remove Drwtsn32.exe malware from system using Comodo Free Antivirus?

Step 1: Download the award-winning Comodo Free Antivirus.

Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.

Step 3: After network detection is complete, press “Close” button for a scan window.

Step 4: Restart your PC.

Step 5: It will take some time for the Comodo Internet Security to update the antivirus.

Step 6: Proceed with a quick scan that automatically begins after the update.

Step 7: If threats are found during the scanning, you will be prompted with an alert screen.

Step 8: Comodo Antivirus will remove Drwtsn32.exe  malware from your computer including all other malwares!

52

Malware Entries

First Seen: 08 October 2011 at 8:48 am
No. Company File Type SHA1 MD5 Malware
Name
Digitally
Signed
File
Version
Product
Version
Submitted
From
Malware Behavior
1 Microsoft Corporation Executable 200f13cef64c8441
268a7224cebb7e72
a07745f0
efc2fd2ef2c0f1e6
01faa5445ad50788
Virus.Win32.
Virut.q
No 5.1.2600.0
(XPClient.
010817-114
8)
5.1.2600.0 Taiwan N/A
2 Microsoft Corporation Executable 0ed3f9ed8c56d649
0c6c5b5f1cd9209c
a9d30ce7
426a41117333b84c
3a9982906e7ea6b2
Virus.Win32.
Virut.CE
No 5.1.2600.0
(XPClient.
010817-114
8)
5.1.2600.0 197.38.155.43/32 N/A
3 Microsoft Corporation Executable d0fcb0a10f1bbe46
90282263fde25473
3b8aa52d
32e5a05bdf3e8734
f686b095ab3057df
Virus.Win32.
Virut.CE
No 5.1.2600.0
(XPClient.
010817-114
8)
5.1.2600.0 Egypt N/A
4 N/A Executable 0835b0047c295345
288db5dba886026b
b713b11d
dce137a731cfe5a8
126626e7242f0138
Backdoor.Win
32.Poison.as
No N/A N/A Canada N/A
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
13

Safe Entries

First Seen: 06 July 2009 at 6:58 am
No. Company File Type SHA1 MD5 Digitally
Signed
File
Version
Product
Version
Submitted
From
1 Microsoft Corporation Executable 591691611bf9bcc7
ec6a355dcce6a30d
caba97ca
f7337c4bfa86c22e
ad1995dbcf3e912a
No 4.00 4.00 United States
2 N/A Non-executable 791bc14921898a06
8f7a23a120c6dbb3
a3b5e989
b44d1e95a4c70853
230a2e1cd0dac0b9
No N/A N/A United States
3 N/A Non-executable b1b9fa209e4d4cfa
df0f09f201f8f452
11c608af
db78a65db033ec7f
76816a9bcbc63308
No N/A N/A China
4 N/A Executable b72c2ae9931bc654
2fabadae02151af1
6c4830f9
9ffd295556d2cdfb
016d7c62cf07f58b
No N/A N/A Bulgaria
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
 
Exclusive Offer
Get Free Endpoint Protection
Get Advanced
Endpoint
Protection

Award-Winning Security to Protect Your Clients from Cyber Attacks

Comodo Internet Security Pro

Antivirus Protection protection from hackers! Get the ultimate Antivirus solution to keep your PC clean and to remove viruses from a slow or infected PC. Improve the PC performance at home or use it on-the-go!

Get Comodo Internet Security Comodo Internet Security