Home Malware Programs Trojans Dfinject CA

Dfinject CA

Posted: May 21, 2009

Dfinject CA (known to Symantec as Backdoor.Trojan, Kaspersky as Backdoor.Win32.Hupigon.gjto, CA AV as Win32/DfInject.CA, and McAfee as BackDoor-AWQ.b) is a Trojan that slips through your system's backdoor vulnerabilities. Once Dfinject CA sneaks into your computer, the Trojan may install additional malware and adware onto the compromised machine.

Aliases

BackDoor-AWQ.b (McAfee)
Backdoor.Trojan (Symantec)
Backdoor.Win32.Hupigon.gjto (Kaspersky)
Win32/DfInject.CA (CA AV)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %system%\waysver.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tapicccaidHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tapicccaid nextinstanceHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tapicccaid\0000HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tapicccaid\0000 classHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tapicccaid\0000 classguidHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tapicccaid\0000 configflagsHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tapicccaid\0000 devicedescHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tapicccaid\0000 legacyHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tapicccaid\0000 serviceHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tapicccaid\0000\controlHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tapicccaid\0000\control *newlycreated*HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tapicccaid\0000\control activeserviceHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaidHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid descriptionHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid displaynameHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid errorcontrolHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid imagepathHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid objectnameHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid startHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid typeHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid\enumHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid\enum 0HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid\enum countHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid\enum nextinstanceHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid\securityHKEY_LOCAL_MACHINE\system\currentcontrolset\services\tapicccaid\security security
Loading...