Backdoor

Backdoor:Win32/Wencho.A removal

Malware Removal

The Backdoor:Win32/Wencho.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Wencho.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Wencho.A?


File Info:

crc32: 534FF1BA
md5: ccd6303e4a52183eab57f98dc4ec0b2d
name: CCD6303E4A52183EAB57F98DC4EC0B2D.mlw
sha1: 63db4b65560a0fa79ca0c0b6449131e80ce8a210
sha256: ddfaa03b309c9cdd6c1cc560c452084e9bf35e0dd3e42efe9627d756a40a9408
sha512: fcaff34e8701262e7b13fa9d533ff4831c447d852812c08b7e6d1262fead061b5887056ad900405f33cc85224d28c54e366c743481a87dcccd0fbeb46a651175
ssdeep: 6144:iGEWzFEs5t38dX6pdE4zU7kpYTcnFOHuln+Otc+EkzI8jSejCE8aKP3sGvLAhcyP:inKSVSF21AJqdzH/pOuGowRR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Wencho.A also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebPowerShell.DownLoader.83
MicroWorld-eScanDropped:Heur.BZC.MNT.Boxter.532.0B271FE3
Qihoo-360Win32/RootKit.Rootkit.7e5
ALYacDropped:Heur.BZC.MNT.Boxter.532.0B271FE3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderDropped:Heur.BZC.MNT.Boxter.532.0B271FE3
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e4a521
BitDefenderThetaGen:NN.ZexaF.34804.w8Y@aSbEuOh
SymantecML.Attribute.HighConfidence
AvastWin32:Rootkit-gen [Rtk]
ClamAVWin.Malware.Razy-9781962-0
KasperskyHEUR:Trojan.PowerShell.Generic
NANO-AntivirusTrojan.Win32.Paph.epaojp
Ad-AwareDropped:Heur.BZC.MNT.Boxter.532.0B271FE3
SophosML/PE-A + ATK/Veil-B
ComodoMalware@#1axs345m2to75
F-SecureHeuristic.HEUR/AGEN.1121977
ZillyaDownloader.Paph.Win32.193
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
SentinelOneStatic AI – Suspicious PE
FireEyeGeneric.mg.ccd6303e4a52183e
EmsisoftDropped:Heur.BZC.MNT.Boxter.532.0B271FE3 (B)
IkarusBackdoor.Win32.Wencho
JiangminTrojan.Generic.azmuq
AviraHEUR/AGEN.1121977
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftBackdoor:Win32/Wencho.A
ArcabitHeur.BZC.MNT.Boxter.532.0B271FE3
ZoneAlarmHEUR:Trojan.PowerShell.Generic
GDataDropped:Heur.BZC.MNT.Boxter.532.0B271FE3
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Paph.C1961981
McAfeeGenericRXAA-AA!CCD6303E4A52
MAXmalware (ai score=84)
VBA32BScope.TrojanSpy.Keylogger
MalwarebytesMalware.AI.1423218576
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of PowerShell/Rozena.BE
RisingBackdoor.Wencho!8.186C (RDMK:cmRtazoEELjdPlajweI96JWymG8X)
YandexTrojan.GenAsa!HzavbW04PD0
FortinetW32/Generic!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml

How to remove Backdoor:Win32/Wencho.A?

Backdoor:Win32/Wencho.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment