Home Malware Programs Backdoors Backdoor-CEP.gen.r

Backdoor-CEP.gen.r

Posted: February 28, 2011

Backdoor-CEP.gen.r is hostile malware primarily identified as a virus, but Backdoor-CEP.gen.r also has traits of a worm and a backdoor Trojan. The Backdoor-CEP.gen.r infection can infect most Windows systems including Windows 7 and runs in the background through registry modifications. Computers infected by Backdoor-CEP.gen.r may suffer from modified system executables, in addition to being assaulted by additional malware downloaded by the infection. Between all these harmful functions and the fact that this infection serves as a tool for remote attackers, removing Backdoor-CEP.gen.r from your machine is a job to take very seriously and avoid putting off.

Putting an Origin to the Backdoor-CEP.gen.r Peril

The history of infection for Backdoor-CEP.gen.r strongly suggests an Indian origin and distribution, so one should pay close attention to unsecured file sources from that area. Backdoor-CEP.gen.r is able to use worm-like methods of infection by copying itself to new drives and abusing Autorun functions; this makes removable drive devices highly vulnerable to Backdoor-CEP.gen.r infection. Even though that's bad enough by itself, Backdoor-CEP.gen.r has also been reported to have virus-like functions, and can modify system .exe files and infect them with copies of itself.

These sophisticated and multi-layered means of infection are further enabled by Backdoor-CEP.gen.r's relatively quiet existence on the machine Backdoor-CEP.gen.r infects. Any Backdoor-CEP.gen.r infection will run in the background, with only the unfamiliar processes in memory and additions to the registry file being clear evidence of its existence.

Backdoor-CEP.gen.r will target very old Windows operating systems, as well as newer ones like Windows 7, but so far hasn't been indicated to attack non-Windows systems. Other common detection names for Backdoor-CEP.gen.r include but aren't restricted to Trojan.Dropper, VirTool:Win32/Injector.gen!Y, Virus:Win32/Mabezat.B, BKDR_BIFROSE.DZZ and VirTool:Win32/CeeInject.gen!W.

Handling the Problems Backdoor-CEP.gen.r Dishes Out

Systems infected by Backdoor-CEP.gen.r will be at risk for the following attacks, at a minimum:

  • Additional malware invasion. Backdoor-CEP.gen.r will download and run files without the user's permission. This can lead to an effectively endless rainbow of attacks on the machine in question, with correspondingly massive damage and loss of privacy.
  • Remote attacks. Backdoor-CEP.gen.r contains tools for remote administration, which when abused allow criminals to take over a computer that has this infection. One common means of remote attack is to enslave the computer into a botnet 'army,' which performs unlawful DDoS attacks without the user having any say in the matter. This is merely one flashy attack out of many often worse possibilities, however.
  • Crippled security programs and settings. Backdoor-CEP.gen.r is essentially required to reduce your security just to get its duties done, and Backdoor-CEP.gen.r will do so without getting any input from you about it. Common security attacks include opening ports to allow outbound and inbound traffic, hijacking the browser to redirect it to dangerous websites and shutting down security programs that could potentially delete Backdoor-CEP.gen.r.

Problems like these, combined with Backdoor-CEP.gen.r's many propagation methods, make this infection a high-level problem for anyone who comes in contact with Backdoor-CEP.gen.r. Do your best to use reliable, proven anti-malware tactics to delete Backdoor-CEP.gen.r, or you may find your computer overwhelmed in short order.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %PROGRAM_FILES%\Backdoor-CEP.gen.r
    2 c:\Documents and Settings\All Users\Backdoor-CEP.gen.r\
    3 c:\Documents and Settings\All Users\Start Menu\Backdoor-CEP.gen.r\

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\Backdoor-CEP.gen.r
Loading...