Trojan

What is “Trojan.Weecnaw”?

Malware Removal

The Trojan.Weecnaw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Weecnaw virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Weecnaw?


File Info:

crc32: 93BE5E16
md5: 7685624fbf77b0cb499e2c93999e8cc4
name: 7685624FBF77B0CB499E2C93999E8CC4.mlw
sha1: d80b12a5b48f712d0ce4df0489dc71dfe75733d5
sha256: be925bd7e4e08ffee7202b703396accc8841c3107d8007ed60b0aefe6935546c
sha512: 619bea8402cad0f2f6a03220aa2471166894e8cc6e95871f81ba7436784c62e4a387865df76b387fc13999d911850299e18721d676c2338ae27b3d1706e2acd5
ssdeep: 1536:gqe7PxaZmgHPQkcRIs9DlqnfZieA8piJBB+fjGaqSCJqHJbq:gqe7PimgHPQkE5qfZieAMiJ6jQ
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.Weecnaw also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.7747
FireEyeGeneric.mg.7685624fbf77b0cb
ALYacGen:Variant.Fugrafa.7747
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 004b89b01 )
BitDefenderGen:Variant.Fugrafa.7747
K7GWSpyware ( 004b89b01 )
CrowdStrikewin/malicious_confidence_80% (D)
TrendMicroTrojanSpy.Win32.WEECNAW.SMUM
CyrenW32/Fsysna.C.gen!Eldorado
SymantecInfostealer
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Malware.Razy-6703914-0
KasperskyTrojan-Spy.Win32.Recam.aeng
RisingBackdoor.NetWire!1.B84F (CLASSIC)
Ad-AwareGen:Variant.Fugrafa.7747
EmsisoftGen:Variant.Fugrafa.7747 (B)
ComodoTrojWare.Win32.Weecnaw.A@7510jd
F-SecureTrojan.TR/Spy.Gen
DrWebBackDoor.Wirenet.562
InvinceaML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
IkarusTrojan-Spy.Agent
JiangminTrojan.Generic.awntg
WebrootW32.Trojan.Gen
AviraTR/Spy.Gen
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/NetWire.YL
ArcabitTrojan.Fugrafa.D1E43
ZoneAlarmTrojan-Spy.Win32.Recam.aeng
GDataGen:Variant.Fugrafa.7747
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Recam.R203280
Acronissuspicious
McAfeePWS-FCNC!7685624FBF77
VBA32BScope.TrojanSpy.Loyeetro
MalwarebytesTrojan.Weecnaw
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Spy.Weecnaw.P
TrendMicro-HouseCallTrojanSpy.Win32.WEECNAW.SMUM
YandexTrojan.GenAsa!ymMgwSYdqKs
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AP.ABA36!tr
BitDefenderThetaAI:Packer.EF9FEEF41E
AVGFileRepMalware
Cybereasonmalicious.fbf77b
Qihoo-360HEUR/QVM20.1.3FBB.Malware.Gen

How to remove Trojan.Weecnaw?

Trojan.Weecnaw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment