Trojan

How to remove “Trojan.Win32.Wecod.all”?

Malware Removal

The Trojan.Win32.Wecod.all is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Wecod.all virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Wecod.all?


File Info:

name: 3064C2D648E5F4403F97.mlw
path: /opt/CAPEv2/storage/binaries/622eb88a692dfb1157ca8c909af49abded9e8ec591be379d0f926570fd8c3603
crc32: CE299BAD
md5: 3064c2d648e5f4403f97e8213a3fb70c
sha1: bff2cd699214827892e7305ba0e529d334dffde6
sha256: 622eb88a692dfb1157ca8c909af49abded9e8ec591be379d0f926570fd8c3603
sha512: dc74f7ad150dc269aa32ce4e3474c9c09973e52c32209fc00f85bff8cdfbb6983750452e857315f4db88eeec23adedadf54153874f60246b997460591f024345
ssdeep: 3072:jBcyGvCKY6PYTZeAgYjPWrtfb5outzQIN3C9ISE0qJiNlUtcW4UV:7s+SYPPWrnoSzQISzqJBcG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10424DF52A6008898F71D0B725907F6E408998E7D68D4F15FF43CBE36A8722971EB724F
sha3_384: 42a02149a062e09ade674883dd853bf4329eb4497b8a437e9bd696f0f9160250b0c183672fc65a027851973bb29e6f55
ep_bytes: 60be003048008dbe00e0f7ff5789e58d
timestamp: 2013-09-08 04:52:30

Version Info:

0: [No Data]

Trojan.Win32.Wecod.all also known as:

tehtrisGeneric.Malware
DrWebTrojan.AVKill.63827
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
FireEyeGeneric.mg.3064c2d648e5f440
CAT-QuickHealTrojan.Urelas.B6
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 00588d7d1 )
K7GWSpyware ( 00588d7d1 )
Cybereasonmalicious.648e5f
ArcabitTrojan.Mint.SP.Urelas.1
BitDefenderThetaGen:NN.ZexaF.34712.nmHfa0S!RsiO
VirITTrojan.Win32.Generic.CONR
CyrenW32/CardSpy.I.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.CardSpy.NAF
ZonerProbably Heur.ExeHeaderL
APEXMalicious
KasperskyTrojan.Win32.Wecod.all
BitDefenderGen:Heur.Mint.SP.Urelas.1
NANO-AntivirusTrojan.Win32.Wecod.fmwmwh
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.CardSpy.16000130
Ad-AwareGen:Heur.Mint.SP.Urelas.1
SophosML/PE-A + Troj/Cardspy-G
ComodoTrojWare.Win32.Urelas.E@51wwjn
BaiduWin32.Trojan.Urelas.d
ZillyaTrojan.FakeAV.Win32.314405
McAfee-GW-EditionBehavesLike.Win32.Corrupt.dc
Trapminesuspicious.low.ml.score
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Wecod.dh
AviraTR/Crypt.Agent.PXL
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.13IJRMU
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Plite.R81822
Acronissuspicious
McAfeeGenericRXAA-AA!3064C2D648E5
MAXmalware (ai score=84)
VBA32Trojan.AVKill
MalwarebytesUrelas.Spyware.Stealer.DDS
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
IkarusTrojan.Win32.Gupboot
FortinetW32/Wecod.ALL!tr
AVGWin32:TrojanX-gen [Trj]
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Win32.Wecod.all?

Trojan.Win32.Wecod.all removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment