Home Malware Programs Backdoors Backdoor:Win32/Votwup.B

Backdoor:Win32/Votwup.B

Posted: July 11, 2011

Backdoor:Win32/Votwup.B is a backdoor Trojan that drills holes in your PC's network security that can be exploited by remote attackers. Backdoor:Win32/Votwup.B has also been seen starting itself automatically, opening network ports, contacting remote hosts, communicating with malicious websites and downloading files without consent. Even taken individually, these attributes are serious risks to your security, but taken together, they turn Backdoor:Win32/Votwup.B into an extreme computer security threat. Fortunately, any good anti-virus application can delete Backdoor:Win32/Votwup.B, provided you've taken measures to stop Backdoor:Win32/Votwup.B from being active during the removal process.

Examining the Wounds That Backdoor:Win32/Votwup.B Can Gouge Into Your Network Security

Being a backdoor Trojan, Backdoor:Win32/Votwup.B's foremost goal is to grab your network security and rip it to shreds. Although the damage that Backdoor:Win32/Votwup.B can cause is potentially significant, observable signs of these attacks are minimal. Backdoor:Win32/Votwup.B attacks can include:

  • Launching itself without your permission. This is a Registry-based exploit that Backdoor:Win32/Votwup.B can set to trigger whenever Windows starts, so that Backdoor:Win32/Votwup.B will remain active on a continual basis.
  • Opening network ports. Open ports will allow information to be sent through them in both directions, making your PC vulnerable to other attacks by remote hackers.
  • Backdoor:Win32/Votwup.B can exploit the above port changes to make contact with remote hosts and malicious websites like mwas.ru. This can be for the purpose of installing other harmful programs, sending confidential information to criminals, receiving configuration data or allowing remote attacks to occur. Remote attacks are responsible for DDoS botnet crimes and other illegal and potentially self-destructive online activities.
  • Backdoor:Win32/Votwup.B has also been observed to download files without your permission, potentially for the purpose of installing other types of harmful applications such as worms, viruses, keyloggers or ransomware.

How to Notice Backdoor:Win32/Votwup.B's Back Door Creaking Open

Backdoor:Win32/Votwup.B and other backdoor Trojans are designed to operate without being noticed. Other than the relevant files and Registry changes, there might not be any visible symptoms of a Backdoor:Win32/Votwup.B infection. However, you may be able to note some of Backdoor:Win32/Votwup.B's attacks by their minor side effects.

Open ports can be monitored with standard network-monitoring programs and a variety of online utilities. By default, ports should be closed; a port should only be open if it's required for a specific program that you've confirmed to be safe.

Attacks on firewalls are also common for Backdoor:Win32/Votwup.B and similar Trojans. These can be exemplified in special program-based 'exceptions' created in your firewall that allow Backdoor:Win32/Votwup.B and other PC threats to ignore your security. In extreme cases, your firewall may be completely disabled instead of having exceptions tunnel through it.

Backdoor:Win32/Votwup.B can be detected with several variant names, depending on the type of security program you use to find a Backdoor:Win32/Votwup.B infection. Other Backdoor:Win32/Votwup.B names include Trojan.Win32.Scar.dyia, Mal/DelpDldr-F and Trojan.Win32.NucScan.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\system\ddid
    2 %Windir%\system\gmfill.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Darkness = ""%Windir%\system\gmfill.exe""HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ExplorerHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
Loading...