Home Malware Programs Worms Worm:Win32/Wecykler.A

Worm:Win32/Wecykler.A

Posted: December 6, 2012

Threat Metric

Threat Level: 5/10
Infected PCs: 4,942
First Seen: December 6, 2012
Last Seen: February 16, 2019
OS(es) Affected: Windows

Worm:Win32/Wecykler.A is a worm that circulates via removable drives, such as USB sticks. Worm:Win32/Wecykler.A also terminates some security related processes, and logs keystrokes. Once installed, Worm:Win32/Wecykler.A drops potentially malicious files and makes registry modifications on the infected computer system. Worm:Win32/Wecykler.A creates copies of itself in the certain locations on the victimized computer system. The folders where the copies of Worm:Win32/Wecykler.A are located are hidden. Worm:Win32/Wecykler.A also creates a hidden copy of itself by dropping a certain file. Worm:Win32/Wecykler.A periodically checks removable drives, for example, USB sticks, floppy drives, and flash card readers. If one is found, Worm:Win32/Wecykler.A replicates itself into this drive, using similar file name as that of the running malware threat. Worm:Win32/Wecykler.A uses a folder icon for its copy in order to fool you into believing that it is simply a folder. Worm:Win32/Wecykler.A logs keystrokes and terminate security-related processes on the targeted PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 303.16 KB (303163 bytes)
MD5: 06c4cf16990f9b5656d63aeab36cf787
Detection count: 539
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 421.88 KB (421888 bytes)
MD5: dc2b102bf65a959abf2849600d8b7a64
Detection count: 164
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 335.87 KB (335872 bytes)
MD5: 7bcc7729483f4819b7b7c6a713f955f7
Detection count: 141
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 323.58 KB (323584 bytes)
MD5: 3a95dd3a3cd7291158d2b205a279035e
Detection count: 98
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: July 12, 2019
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 446.46 KB (446464 bytes)
MD5: f541bdb6f99f14fb4925553894cd38d8
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 344.06 KB (344064 bytes)
MD5: a04d1caa64ed4d6e025c3dd6ea7f45d4
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 458.75 KB (458752 bytes)
MD5: 563713b0bc0cdaabb6fa8575f96dae1b
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 450.56 KB (450560 bytes)
MD5: 8fa3a8088782f9e096d2af0dc2a1d327
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 631.12 KB (631121 bytes)
MD5: 0a689879448eb8df6ded1692615c3fa1
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 426.24 KB (426240 bytes)
MD5: db308e7c392c367a0621c9049a49522a
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 330.12 KB (330121 bytes)
MD5: 8f3a8c8a8560190322b65a39f4d9f0d6
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 393.21 KB (393216 bytes)
MD5: f2812e3112f2eca13e0a2a7d4a2cab12
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 610.3 KB (610304 bytes)
MD5: e4e872bb08753ed17164878f96d7a5fd
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 397.31 KB (397312 bytes)
MD5: 83101677c2add0255e0cf44945ec6b29
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 348.67 KB (348678 bytes)
MD5: 9e8839545b04f6bc489e9e1b98010858
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 405.5 KB (405504 bytes)
MD5: 95bcf1dc23eef9c392283d5c9eb27d03
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 328.19 KB (328198 bytes)
MD5: 07e09ae0fca7269f1653d8fc7b40b6a1
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 368.64 KB (368640 bytes)
MD5: 3d443e603a14e42e32b8bd89ae98c6ec
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 380.92 KB (380928 bytes)
MD5: 78f14a579f001c10baf9e124c6248146
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 323.58 KB (323584 bytes)
MD5: 8ba7d5d58900861211f0804a6d7cc415
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
%SystemDrive%\Program Files\Windows Alerter\WinAlert.exe File name: WinAlert.exe
Size: 425.98 KB (425984 bytes)
MD5: 49971f4afa835fc283e60892c1327899
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\Windows Alerter
Group: Malware file
Last Updated: May 16, 2017
C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\WinSysApp.exe File name: C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\WinSysApp.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\info File name: C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\info
Group: Malware file
%ProgramFiles%\Windows Alerter\WinAlert.exe File name: %ProgramFiles%\Windows Alerter\WinAlert.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\Windows Common Files\Commgr.exe File name: %ProgramFiles%\Windows Common Files\Commgr.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "WindowMessenger" = "C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\WinSysApp.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""Windows Common Files Manager" = "%ProgramFiles%\Windows Common Files\Commgr.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Alerter" = "%ProgramFiles%\Windows Alerter\WinAlert.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WindowMessenger" = "C:\RECYCLER\X-1-5-21-1960408961-725345543-839522115-1003\WinSysApp.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run ""Windows Common Files Manager"" = "%ProgramFiles%\Windows Common Files\Commgr.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Windows Alerter" = "%ProgramFiles%\Windows Alerter\WinAlert.exe"
Loading...