Trojan

Trojan.Win32.Wecod.jdqw (file analysis)

Malware Removal

The Trojan.Win32.Wecod.jdqw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Wecod.jdqw virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Wecod.jdqw?


File Info:

name: 6E951FB55AFA8F46FA85.mlw
path: /opt/CAPEv2/storage/binaries/8114a93bfed41bff1815711891f1639aadcf5a522dd04e21f30c2de0b5ab9adb
crc32: 6A93982F
md5: 6e951fb55afa8f46fa85ca1716c60357
sha1: 88bfc55e19f778abda57c7d72b5f38d656489ee1
sha256: 8114a93bfed41bff1815711891f1639aadcf5a522dd04e21f30c2de0b5ab9adb
sha512: 14cf38f52fa08c9e135c2ab9d01763d5dcc9b29a3e75c3f4ad8be7f1ab61a7edf36e652b6ed526a88c0840e88e0325b655d09839f4d2a48e4e920a0dc94c6975
ssdeep: 6144:fQw4e5PcawcjQi/rWl8sOPMA6A+xLQWsi9VqRn6Rw0Z9BPNxvI:fLv5EGHsuMFA+xcWsiDwCf1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172F47B317280C071E35513740957E2B15AAE6E384BA9A6CFF6A43E391E313D39B7724E
sha3_384: 432494250e350f715a936c4e48c82e454c68bb299fc32680d72a8499d4adf5f4718784e7ba1d84162b2b0ca78e0d3718
ep_bytes: 8ef489448ff48b448ef889448ff88b44
timestamp: 2013-10-14 03:32:42

Version Info:

0: [No Data]

Trojan.Win32.Wecod.jdqw also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.32763
MalwarebytesCardSpy.Spyware.Stealer.DDS
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
APEXMalicious
ClamAVWin.Malware.Mikey-9891201-0
KasperskyTrojan.Win32.Wecod.jdqw
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.CardSpy.16000130
F-SecureTrojan.TR/Spy.Cardspy.vkmqv
BaiduWin32.Trojan.Urelas.d
McAfee-GW-EditionBehavesLike.Win32.Generic.bt
FireEyeGeneric.mg.6e951fb55afa8f46
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.102K66A
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
XcitiumTrojWare.Win32.Urelas.ASE@5izxb0
ZoneAlarmTrojan.Win32.Wecod.jdqw
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4086090
McAfeeArtemis!6E951FB55AFA
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BH0CD723
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
IkarusTrojan.Win32.Beaugrit
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CardSpy.PRKJ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Wecod.jdqw?

Trojan.Win32.Wecod.jdqw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment