Malware

Application.WUC (file analysis)

Malware Removal

The Application.WUC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.WUC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.WUC?


File Info:

name: 7E3360F658695AD482E8.mlw
path: /opt/CAPEv2/storage/binaries/5999d36ebde2c21b33d5cb2b43a00cfd51dd50adde1393bd98537277204c29dc
crc32: DB3F8BAA
md5: 7e3360f658695ad482e887ee838440ba
sha1: b1c9fef009a409e62e99f63c5ed39864e40dde1d
sha256: 5999d36ebde2c21b33d5cb2b43a00cfd51dd50adde1393bd98537277204c29dc
sha512: 2555fd7ce0c7c5eb35eac0925c6ba023b6b1f14b97735101bb70f9ddda2b24600282d0072267d450f95a02cd0fc72042ba85da9ffae676bcc92d0dc8c4253918
ssdeep: 12288:Y1XFmScL/gMOIpph74JBYaPfs62qg17utZkdBrosssS:aXQSk/gMqlf27wudBrrssS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AF41201B585F4B1D0B64A332832AEB0AD7D7A640F9049AB678DD73F4E384D15B73A32
sha3_384: a1dd90204d214c8b50c773bf2fa5703b2b2ca0c341677e782587d11b5e8a1d0d22c459c37f257e323261c96ea3dc20ea
ep_bytes: e8f4040000e98efeffff558becff7508
timestamp: 2017-11-12 11:45:13

Version Info:

FileVersion: 1.0.0.1
LegalCopyright: Copyright (C) 2017
ProductVersion: 3.0.0.1
Translation: 0x0419 0x04b0

Application.WUC also known as:

BkavW32.AIDetectMalware
AVGWin32:AdwareX-gen [Adw]
tehtrisGeneric.Malware
MicroWorld-eScanApplication.WUC
FireEyeGeneric.mg.7e3360f658695ad4
CAT-QuickHealSwBundler.Prepscram.EMU.Y7
SkyhighBehavesLike.Win32.Generic.bh
ALYacApplication.WUC
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00528e801 )
K7GWTrojan ( 0051bd081 )
Cybereasonmalicious.658695
SymantecPUA.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HPOT
CynetMalicious (score: 99)
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderApplication.WUC
NANO-AntivirusRiskware.Win32.StartSurf.euxmer
AvastWin32:AdwareX-gen [Adw]
RisingTrojan.Kryptik!1.AEAF (CLASSIC)
SophosGeneric ML PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1307835
DrWebTrojan.Vittalia.13633
VIPREApplication.WUC
Trapminemalicious.high.ml.score
EmsisoftApplication.WUC (B)
IkarusPUA.WUC
JiangminAdWare.StartSurf.ahj
WebrootW32.Adware.Gen
VaristW32/S-004cd42d!Eldorado
AviraHEUR/AGEN.1307835
Antiy-AVLGrayWare[AdWare]/Win32.StartSurf
Kingsoftmalware.kb.a.1000
MicrosoftSoftwareBundler:Win32/Prepscram
XcitiumApplication.Win32.IStartSurf.FH@7dkgjq
ArcabitApplication.WUC
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataApplication.WUC
GoogleDetected
AhnLab-V3Adware/Win32.StartSurf.R213022
Acronissuspicious
McAfeePacked-UT!7E3360F65869
MAXmalware (ai score=78)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10b29ac5
YandexTrojan.GenAsa!H6V/gGIF+XE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.11574264.susgen
FortinetW32/Kryptik.GFGF!tr
BitDefenderThetaGen:NN.ZexaF.36802.Uu0@ay1J9Koi
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_90% (D)
alibabacloudPUA.Win.Prepscram.c2937cfd

How to remove Application.WUC?

Application.WUC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment