Home Malware Programs Backdoors Backdoor.RDPopen.A

Backdoor.RDPopen.A

Posted: August 30, 2012

Threat Metric

Threat Level: 6/10
Infected PCs: 1,305
First Seen: August 30, 2012
OS(es) Affected: Windows

Backdoor.RDPopen.A is a backdoor Trojan that can destroy the targeted computer system. Backdoor.RDPopen.A allows attackers to gain full remote access and control over the compromised PC. Backdoor.RDPopen.A downloads and installs other PC threats on the infected machine. Backdoor.RDPopen.A may invade the corrupted PC alongside with another malicious application. Malicious components of Backdoor.RDPopen.A can disable important system tool, such as Windows Registry Editor, Task Manager, and Safe Mode.

Aliases

TrojWare.Win32.Trojan.Agent.Gen [Comodo]Trj/CI.A [Panda]unknown virus Win32/DH{A2IJJwE} [AVG]W32/Agent.PEB [Fortinet]Backdoor.Win32.RDPopen [Ikarus]ASD.Prevention [AhnLab-V3]Trojan.FakeAV.13384 [DrWeb]HEUR:Trojan.Win32.Generic [Kaspersky]Artemis!EE6A3B4F760A [McAfee]BackDoor.Generic15.BANY [AVG]W32/Jorik_Lethic.XM!tr [Fortinet]Backdoor.Win32.DarkKomet [Ikarus]Trojan/Win32.Jorik [AhnLab-V3]Trojan/Win32.Jorik.gen [Antiy-AVL]Heuristic.LooksLike.Win32.Suspicious.B [McAfee-GW-Edition]
More aliases (190)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\AV Protection 2012\securitycenter.exe File name: securitycenter.exe
Size: 3.82 MB (3826179 bytes)
MD5: 8f5d347281fe3557c41cb89d8d2a8d87
Detection count: 422
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\AV Protection 2012
Group: Malware file
Last Updated: September 3, 2012
%APPDATA%\msconfig.dat File name: msconfig.dat
Size: 80.38 KB (80384 bytes)
MD5: 3adb6173bced3d1a78b340e1f3e96fba
Detection count: 23
File type: Data file
Mime Type: unknown/dat
Path: %APPDATA%
Group: Malware file
Last Updated: September 3, 2012
%TEMP%\csrssr.exe File name: csrssr.exe
Size: 167.93 KB (167936 bytes)
MD5: a90dcb18e3049e2e117aab02ffdc4684
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: March 29, 2013
%TEMP%\csrssr.exe File name: csrssr.exe
Size: 196.6 KB (196608 bytes)
MD5: a158dfe37c545c99cd2e5b508d9a209f
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: January 21, 2013
%USERPROFILE%\Downloads\tpwSetup-dm.exe File name: tpwSetup-dm.exe
Size: 212.99 KB (212992 bytes)
MD5: 9f892e13257fc8e60bfd703003a61ae8
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Downloads
Group: Malware file
Last Updated: September 3, 2012
%ALLUSERSPROFILE%\IBUpdaterService\ibsvc.exe File name: ibsvc.exe
Size: 395.99 KB (395992 bytes)
MD5: 0ee5e2c67f1996ac0c32abee8533751b
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\IBUpdaterService
Group: Malware file
Last Updated: September 7, 2012
%SystemDrive%\Date.Msi\alg.exe File name: alg.exe
Size: 184.83 KB (184832 bytes)
MD5: e071327a5ec1640b5f3b3bcadc277747
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Date.Msi
Group: Malware file
Last Updated: September 3, 2012
Loading...