Home Malware Programs Trojans Trojan.Weelsof.A

Trojan.Weelsof.A

Posted: July 20, 2012

Threat Metric

Ranking: 16,776
Threat Level: 8/10
Infected PCs: 1,077
First Seen: July 20, 2012
Last Seen: September 22, 2023
OS(es) Affected: Windows

Trojan.Weelsof.A (Trojan:Win32/Weelsof.A) is a Trojan that may be a part of an online scam known as ransomware. Trojan:Win32/Weelsof.A may lock the desktop of the targeted computer and ask PC users to disclose personal information in order to restore the computer to the normal state. Trojan:Win32/Weelsof.A may lock the compromised PC without any possibility to use it. Trojan:Win32/Weelsof.A displays a pop-up warning message, which demands a ransom from PC users to be paid to unlock the infected computer. Once executed, Trojan:Win32/Weelsof.A copies itself into the certain folders using a random file name. Trojan:Win32/Weelsof.A modifies the certain registry entries to allow its copy run automatically every time Windows is started. Trojan:Win32/Weelsof.A connects to numerous websites.

Aliases

Generic28.BCQV [AVG]W32/Kryptik.AGBK [Fortinet]TR/Weelsof.A.15 [AntiVir]Mal/EncPk-ZC [Sophos]Win32:Weelsof-B [Trj] [Avast]a variant of Win32/Kryptik.AGBK [NOD32]Artemis!B02A4E2B1CDA [McAfee]Generic28.ATFL [AVG]TR/Weelsof.A.5 [AntiVir]Trojan-Downloader.Win32.Agent.vxgh [Kaspersky]Generic.dx!b2ot [McAfee]SHeur4.AHSN [AVG]W32/Agent.B!tr.dldr [Fortinet]Mal/Generic-L [Sophos]TR/Weelsof.A.54 [AntiVir]
More aliases (322)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\program files (x86)\common files\element5 shared\service\licence manager esd.exe File name: licence manager esd.exe
Size: 69.12 KB (69120 bytes)
MD5: 4c1a177f07cff8dee3bdbedb9f8713e5
Detection count: 246
File type: Executable File
Mime Type: unknown/exe
Path: c:\program files (x86)\common files\element5 shared\service\licence manager esd.exe
Group: Malware file
Last Updated: January 31, 2023
%ALLUSERSPROFILE%\tttzihrc.exe File name: tttzihrc.exe
Size: 61.44 KB (61440 bytes)
MD5: 83bcd99a21d36cc716384e34a1862d4c
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 21, 2012
%ALLUSERSPROFILE%\cgknxlgi.exe File name: cgknxlgi.exe
Size: 77.82 KB (77824 bytes)
MD5: 704a15b99df6a3055a06deefaa39eaf8
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 25, 2012
%ALLUSERSPROFILE%\dvfoqfhdvfkftequmggv.exe File name: dvfoqfhdvfkftequmggv.exe
Size: 57.34 KB (57344 bytes)
MD5: b02a4e2b1cda9e6835592d390e750d48
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: May 8, 2013
%PROGRAMFILES%\Power DVD Player\PowerDVDPlayer.exe File name: PowerDVDPlayer.exe
Size: 391.16 KB (391168 bytes)
MD5: 58eddfec65b6aa166fc7ff4a442cc4b5
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Power DVD Player
Group: Malware file
Last Updated: June 8, 2020
%ALLUSERSPROFILE%\ilsdcfch.exe File name: ilsdcfch.exe
Size: 65.53 KB (65536 bytes)
MD5: 1a8abfef8f8686e235f473769117b0d4
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: July 24, 2012
%ALLUSERSPROFILE%\Application Data\mbipokqz.exe File name: mbipokqz.exe
Size: 49.15 KB (49152 bytes)
MD5: 3c6248c6963fc65cba11b9d2914f621a
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: July 26, 2012
C:\Program Files\Eset\MiNODLogin\MiNODLogin.exe File name: MiNODLogin.exe
Size: 125.95 KB (125952 bytes)
MD5: 529811128129f16da634e11c25b98800
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Eset\MiNODLogin\MiNODLogin.exe
Group: Malware file
Last Updated: July 13, 2022
%ALLUSERSPROFILE%\Application Data\czsjhctk.exe File name: czsjhctk.exe
Size: 73.72 KB (73728 bytes)
MD5: 9cc0377a6856f90a049cfb9c45a0fcd1
Detection count: 34
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: July 23, 2012
%WINDIR%\update.5.0\svchost.exe File name: svchost.exe
Size: 347.64 KB (347648 bytes)
MD5: 6a826a4b7e91c64bec2963279f21b275
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\update.5.0
Group: Malware file
Last Updated: March 29, 2020
%ALLUSERSPROFILE%\isohxgumckkabivcqaoz.exe File name: isohxgumckkabivcqaoz.exe
Size: 57.34 KB (57344 bytes)
MD5: 078c0719d44e57ef56bfed98500eae34
Detection count: 31
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: December 24, 2012
%ALLUSERSPROFILE%\ubupeqmdjsvkzgotrtpb.exe File name: ubupeqmdjsvkzgotrtpb.exe
Size: 69.63 KB (69632 bytes)
MD5: c4c129fa72b3c0a6364635e33ee3d9b7
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: February 11, 2013
%ALLUSERSPROFILE%\Local Settings\Temp\msadvhwa.scr File name: msadvhwa.scr
Size: 73.72 KB (73728 bytes)
MD5: be7261160a5d54b1e7e65b93afa81ac0
Detection count: 16
Mime Type: unknown/scr
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: October 23, 2012
%ALLUSERSPROFILE%\qakpcxut.exe File name: qakpcxut.exe
Size: 73.72 KB (73728 bytes)
MD5: 8f2aab6d01aed681b3f5e6d03166d0ca
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: July 20, 2012
%ALLUSERSPROFILE%\yrpaoeqs.exe File name: yrpaoeqs.exe
Size: 49.15 KB (49152 bytes)
MD5: 476fedc6f13e716a9111bcad8a4ef403
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: July 30, 2012
%TEMP%\hznn.exe File name: hznn.exe
Size: 43.63 KB (43631 bytes)
MD5: 11928c7843c9a45143aada64a8fc0cb4
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: October 23, 2012
%ALLUSERSPROFILE%\behmrirb.exe File name: behmrirb.exe
Size: 53.24 KB (53248 bytes)
MD5: b087ae3ae79f96f68e1c2755cdabd6d0
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 16, 2012
%ALLUSERSPROFILE%\Application Data\qyljhjnr.exe File name: qyljhjnr.exe
Size: 61.44 KB (61440 bytes)
MD5: 0d813e8c3a8b2091ff6bdd244e621120
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: August 10, 2012
%WINDIR%\winlogon.exe File name: winlogon.exe
Size: 42.49 KB (42496 bytes)
MD5: 198fd5231e3faa1b88a36a6d593b1423
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: October 23, 2012
%WINDIR%\svchost.exe File name: svchost.exe
Size: 42.49 KB (42496 bytes)
MD5: bc311dec8b62ebcc5bb7f77e0b598f43
Detection count: 2
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: October 23, 2012
Loading...