Home Malware Programs Backdoors BackDoor.DaVinci.1

BackDoor.DaVinci.1

Posted: July 27, 2012

Threat Metric

Threat Level: 6/10
Infected PCs: 23
First Seen: July 27, 2012
Last Seen: July 8, 2018
OS(es) Affected: Windows

BackDoor.DaVinci.1 is a backdoor Trojan and rootkit that's newsworthy for the power of its modular design, as well as its cross-platform compatibility with Windows, Mac OS X and several mobile device-specific operating systems. Dubbed by its creators as a 'weapon for the 21st century,' BackDoor.DaVinci.1 grants criminals complete access to the infected PC and can be used for subtle attacks, such as theft of personal information, as well as extremely obvious and damaging attacks that render the system nonoperational. SpywareRemove.com malware researchers rank BackDoor.DaVinci.1, which is being actively distributed and sold to other criminals at this time, as a high-level PC threat that should be removed by the best anti-malware programs that you have available.

BackDoor.DaVinci.1: Chipping Away at Mac's Security Superiority

While it's extremely unusual for rootkits or backdoor Trojans like BackDoor.DaVinci.1 to include compatibility for operating systems besides Windows, BackDoor.DaVinci.1 goes an extra mile by including its rootkit functions for Mac OS X. As the first rootkit identified for that platform, BackDoor.DaVinci.1 can conceal its files and memory processes from normal detection and may be effectively undetectable without anti-malware software to guard your PC on an active basis.

Distribution by BackDoor.DaVinci.1 uses a JAR file with a fraudulent certificate and the (obviously inaccurate) name of 'AdobeFlashPlayer.' SpywareRemove.com malware experts note that downloading software installation files from untrustworthy sources is a prominent means infection vector for many types of PC threats, including BackDoor.DaVinci.1, and it's always recommended for you to download your software from direct and trustworthy sources.

There may not be any symptoms of a BackDoor.DaVinci.1 infection, although is capable of handing over complete control of your computer to outside sources. Because BackDoor.DaVinci.1 uses modules and configuration data to vary its attacks and is sold to a variety of criminals with differing goals in mind, the behavior of any one BackDoor.DaVinci.1 infection may differ from another one. However, SpywareRemove.com malware experts recommend treating all varieties of BackDoor.DaVinci.1 infections as high-level PC threats to be deleted by thorough and quick anti-malware scans.

The Modules That BackDoor.DaVinci.1 Uses to Make You Suffer

BackDoor.DaVinci.1's full capabilities range from attacks as low-key as stealing passwords to attacks as obvious as disabling the affected PC. Some of its most prominent module-based features that SpywareRemove.com malware analysts have noted include:

  • The ability to bypass default security programs, including your firewall and anti-virus protection.
  • A keylogging function that records your keyboard input to a log file that can be sent to criminals for theft of passwords, account names, etc.
  • Screenshot functionality that allows BackDoor.DaVinci.1 to steal nonkeyboard data.
  • Downloader functions that can install other PC threats or update BackDoor.DaVinci.1.
  • Spyware features that allow BackDoor.DaVinci.1 to capture e-mail or mobile text-based information.
  • A webcam and microphone-recording feature.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\Desktop\file.exe File name: file.exe
Size: 6.29 MB (6291472 bytes)
MD5: e99729a13c6bd433c106ebef93f7d27a
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop
Group: Malware file
Last Updated: May 7, 2018
C:\Users\<username>\Desktop\file.exe File name: file.exe
Size: 1.04 MB (1048592 bytes)
MD5: f665626b791abf1e2a54e721a80ca243
Detection count: 49
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop
Group: Malware file
Last Updated: November 14, 2018
C:\Users\<username>\Desktop\file.exe File name: file.exe
Size: 6.29 MB (6291472 bytes)
MD5: 0a9aae712f868137e21353d9a8c9291c
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop
Group: Malware file
Last Updated: August 6, 2018

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ToolwizCares.exe

One Comment

  • Ivan says:

    Somehow Open Cloud security was dewdloanod on to my computer. I have found programs that detect it, but they won't remove the program for free. Are there any programs that will remove it for free? PLEASE HELP

Loading...