Trojan

How to remove “UDS:Trojan.Win32.Weelsof.sdk”?

Malware Removal

The UDS:Trojan.Win32.Weelsof.sdk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan.Win32.Weelsof.sdk virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the RedLine malware family
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Appears to use command line obfuscation
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine UDS:Trojan.Win32.Weelsof.sdk?


File Info:

name: B5CD73721D5B93EE3C7D.mlw
path: /opt/CAPEv2/storage/binaries/09a9fc85eb8bfae64150ff1d42714ebef7ae9c195504805a8287d084d19e0da9
crc32: 380823A9
md5: b5cd73721d5b93ee3c7db07bc1a4184d
sha1: 4ecff0dd636b82f7ff264ee5eec12346e0575c32
sha256: 09a9fc85eb8bfae64150ff1d42714ebef7ae9c195504805a8287d084d19e0da9
sha512: 44a5016f66addebcc53c5bc91a477fb50c8e3f8c7bf37daa6b24c5ca769f8e00a08a6b6530829422f229b8a6c7400aadc1494cea56cec111e7dd48613a2b3edd
ssdeep: 24576:ey2cu9RsLvSg5qOVbsYSyyCsaA+bjneTah6:t2cu66so+p7jeTah
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142152343F7EC4122C9B057B058B602C326367EE56B748B9A234E7C591CB36D8B23576B
sha3_384: 2e7753e40a45637fd94cafac47c922c06cdc62af6bf8b9cd1f9247e994ec5c79969ca526969c7cf6ac920bb01463b9c2
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Самоизвлечение CAB-файлов Win32
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0419 0x04b0

UDS:Trojan.Win32.Weelsof.sdk also known as:

AVGWin32:DropperX-gen [Drp]
Elasticmalicious (high confidence)
FireEyeGeneric.mg.b5cd73721d5b93ee
ALYacGen:Variant.Doina.48991
MalwarebytesGeneric.Trojan.Injector.DDS
VIPRETrojan.GenericKD.65331035
Cybereasonmalicious.21d5b9
CyrenW32/KillAV.KMEF-6536
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
CynetMalicious (score: 99)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Disabler-9987080-0
KasperskyUDS:Trojan.Win32.Weelsof.sdk
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:DropperX-gen [Drp]
TencentTrojan.MSIL.Agent.hg
DrWebTrojan.Siggen19.32857
TrendMicroRansom.Win32.STOP.SMYXDBTB.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
IkarusTrojan-Downloader.Win32.Amadey
AviraTR/Disabler.zxgud
Antiy-AVLTrojan/Script.Phonzy
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGeneric.Trojan.PSEB.2OUO9I
GoogleDetected
McAfeeArtemis!946E45CA9CA5
TrendMicro-HouseCallTROJ_GEN.R002C0PBS23
RisingTrojan.Generic@AI.98 (RDML:BxIBOIcWuJkwycfv4M3O1Q)
YandexTrojan.Disabler!G6z7qDxyklM
SentinelOneStatic AI – Suspicious SFX
FortinetMSIL/Disabler.DR!tr

How to remove UDS:Trojan.Win32.Weelsof.sdk?

UDS:Trojan.Win32.Weelsof.sdk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment