Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Oct 23, 2012 | Updated Jul 11, 2017

Worm:Win32/Wecykler.A

Detected by Microsoft Defender Antivirus

Aliases: Trojan/Win32.Cosmu (AhnLab) Worm.Win32.Fednu.k (Rising AV)

Summary

Windows Defender detects and removes this threat.

Win32/Wecykler.A is a worm that spread via removable drives, such as USBs, that can stop security and other processes on your PC, and log keystrokes which can then be sent to a hacker.

The following Microsoft software detects and removes this threat:

Even if we've already detected and removed this particular threat, running a full scan might find other malware that is hiding on your PC.

Enable the registry editor

This threat might prevent Registry Editor from running. To allow the Registry Editor to run, follow these steps:

  1. Click Start then Run and type cmd to run a command prompt.
  2. In the command prompt, type the following and press Enter:
    reg.exe add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f
  3. Type exit.
Additional remediation instructions for this threat

This threat might make lasting changes to your PC's settings that won't be restored when it's cleaned. The following steps can help change these settings back to what you want:

Follow us