Home Malware Programs Worms Worm:Win32/Wecykler.A

Worm:Win32/Wecykler.A

Posted: December 6, 2012

Threat Metric

Threat Level: 5/10
Infected PCs: 4,942
First Seen: December 6, 2012
Last Seen: February 16, 2019
OS(es) Affected: Windows

Worm:Win32/Wecykler.A is a worm that circulates via removable drives, such as USB sticks. Worm:Win32/Wecykler.A also terminates some security related processes, and logs keystrokes. Once installed, Worm:Win32/Wecykler.A drops potentially malicious files and makes registry modifications on the infected computer system. Worm:Win32/Wecykler.A creates copies of itself in the certain locations on the victimized computer system. The folders where the copies of Worm:Win32/Wecykler.A are located are hidden. Worm:Win32/Wecykler.A also creates a hidden copy of itself by dropping a certain file. Worm:Win32/Wecykler.A periodically checks removable drives, for example, USB sticks, floppy drives, and flash card readers. If one is found, Worm:Win32/Wecykler.A replicates itself into this drive, using similar file name as that of the running malware threat. Worm:Win32/Wecykler.A uses a folder icon for its copy in order to fool you into believing that it is simply a folder. Worm:Win32/Wecykler.A logs keystrokes and terminate security-related processes on the targeted PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 503.8 KB (503808 bytes)
MD5: 6525cd3d78d0b0fd5822feb664a2f9c3
Detection count: 112
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\WinSysApp.exe File name: C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\WinSysApp.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\info File name: C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\info
Group: Malware file
%ProgramFiles%\Windows Alerter\WinAlert.exe File name: %ProgramFiles%\Windows Alerter\WinAlert.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\Windows Common Files\Commgr.exe File name: %ProgramFiles%\Windows Common Files\Commgr.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "WindowMessenger" = "C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\WinSysApp.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""Windows Common Files Manager" = "%ProgramFiles%\Windows Common Files\Commgr.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Alerter" = "%ProgramFiles%\Windows Alerter\WinAlert.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WindowMessenger" = "C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\WinSysApp.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run ""Windows Common Files Manager"" = "%ProgramFiles%\Windows Common Files\Commgr.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Windows Alerter" = "%ProgramFiles%\Windows Alerter\WinAlert.exe"
Loading...