Threat Database Worms Worm:Win32/Wecykler.A

Worm:Win32/Wecykler.A

By LoneStar in Worms

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 2,110
First Seen: December 6, 2012
Last Seen: February 16, 2019
OS(es) Affected: Windows

Worm:Win32/Wecykler.A is a worm that proliferates via removable drives, such as USB sticks. Worm:Win32/Wecykler.A also ends some security related processes, and logs keystrokes. While being installed, Worm:Win32/Wecykler.A adds malevolent files and makes registry modifications on the victimized PC. Worm:Win32/Wecykler.A creates copies of itself in the certain locations on the affected PC. The folders where Worm:Win32/Wecykler.A creates its copies are covered. Worm:Win32/Wecykler.A also creates a covered copy of itself by adding a certain file. Worm:Win32/Wecykler.A periodically checks removable drives, for example, USB sticks, flash card readers and floppy drives. If one is found, Worm:Win32/Wecykler.A copies itself into this drive, using similar file name as that of the running malware infection. Worm:Win32/Wecykler.A uses a folder icon for its copy in order to dupe you into thinking that it is simply a folder.

SpyHunter Detects & Remove Worm:Win32/Wecykler.A

File System Details

Worm:Win32/Wecykler.A may create the following file(s):
# File Name MD5 Detections
1. WinAlert.exe 45deb8250ea992c0551221f0ecb90b3c 1,044
2. WinAlert.exe 06c4cf16990f9b5656d63aeab36cf787 230
3. WinAlert.exe dc2b102bf65a959abf2849600d8b7a64 70
4. WinAlert.exe 7bcc7729483f4819b7b7c6a713f955f7 60
5. WinAlert.exe 3a95dd3a3cd7291158d2b205a279035e 42
6. WinAlert.exe f541bdb6f99f14fb4925553894cd38d8 32
7. WinAlert.exe a04d1caa64ed4d6e025c3dd6ea7f45d4 30
8. WinAlert.exe 563713b0bc0cdaabb6fa8575f96dae1b 30
9. WinAlert.exe 8fa3a8088782f9e096d2af0dc2a1d327 30
10. WinAlert.exe 0a689879448eb8df6ded1692615c3fa1 23
11. WinAlert.exe db308e7c392c367a0621c9049a49522a 20
12. WinAlert.exe 4f7cecb0177b888db4f1577c0014776c 20
13. WinAlert.exe 48733d664783ce96affc619052b74cb2 20
14. WinAlert.exe 8f3a8c8a8560190322b65a39f4d9f0d6 20
15. WinAlert.exe f2812e3112f2eca13e0a2a7d4a2cab12 20
16. WinAlert.exe e4e872bb08753ed17164878f96d7a5fd 11
17. WinAlert.exe b36ef4294ec41f4183a353695486c4e2 10
18. WinAlert.exe 83101677c2add0255e0cf44945ec6b29 10
19. WinAlert.exe 9e8839545b04f6bc489e9e1b98010858 10
20. WinAlert.exe 289e5a19102f198decb7fd01c4b093f5 10
21. WinAlert.exe 95bcf1dc23eef9c392283d5c9eb27d03 10
22. WinAlert.exe 579a5c89e18c7ab1a987e5ec4956c5fe 10
23. WinAlert.exe 07e09ae0fca7269f1653d8fc7b40b6a1 10
24. WinAlert.exe dff875a51b5a5bb3ca9d1df40151f85d 10
25. WinAlert.exe 3d443e603a14e42e32b8bd89ae98c6ec 10
26. WinAlert.exe 78f14a579f001c10baf9e124c6248146 10
27. WinAlert.exe 8ba7d5d58900861211f0804a6d7cc415 9
28. WinAlert.exe 49971f4afa835fc283e60892c1327899 7
29. %ProgramFiles%\Windows Common Files\Commgr.exe
30. %ProgramFiles%\Windows Alerter\WinAlert.exe
31. C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\WinSysApp.exe
32. C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\info
More files

Registry Details

Worm:Win32/Wecykler.A may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Alerter" = "%ProgramFiles%\Windows Alerter\WinAlert.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Windows Alerter" = "%ProgramFiles%\Windows Alerter\WinAlert.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""Windows Common Files Manager" = "%ProgramFiles%\Windows Common Files\Commgr.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run ""Windows Common Files Manager"" = "%ProgramFiles%\Windows Common Files\Commgr.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "WindowMessenger" = "C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\WinSysApp.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WindowMessenger" = "C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\WinSysApp.exe"

Trending

Most Viewed

Loading...