Backdoor:Win32/Caphaw.A
Posted: November 18, 2011
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Threat Level: | 6/10 |
---|---|
Infected PCs: | 70 |
First Seen: | November 1, 2011 |
---|---|
Last Seen: | April 6, 2020 |
OS(es) Affected: | Windows |
Backdoor:Win32/Caphaw.A is a malicious firewall-bypassing backdoor Trojan that propagates via status updates on Facebook. Backdoor.Win32.Caphaw.A targets the Windows platform and allows attackers to gain remote access to the infected PCs. Backdoor:Win32/Caphaw.A can block URL requests in both Firefox and Internet Explorer and is able to post very personable updates on friends' walls in Facebook, obtaining access if the PC user is logged in. The posted message redirects to a video posted on a website similar to Youtube, which offers the user to update the browser with a fake ActiveX object. The video landing page seems to be a legitimate one. The particular download is, in fact, Backdoor:Win32/Caphaw.A, which installs an FTP server, a proxy server, and a keylogger on the targeted computer. Backdoor:Win32/Caphaw. also has a built-in remote desktop functionality based on the open source VNC project. Backdoor:Win32/Caphaw is also known to be able compromise bank accounts and steal money because of the keylogging component, associated with the remote desktop functionality; that's why Backdoor:Win32/Caphaw.A is considered to be an online identity threat. Find a reliable and trustworthy anti-malware tool to uninstall Backdoor:Win32/Caphaw form the infected PC system.
Aliases
More aliases (63)
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:%APPDATA%\Ulead Systems\Ulead VideoStudio\netiougc.exe
File name: netiougc.exeSize: 340.44 KB (340440 bytes)
MD5: 2de054cf7b8f3dab89d6b9cef13f335a
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Ulead Systems\Ulead VideoStudio
Group: Malware file
Last Updated: November 1, 2011
%PROGRAMFILES%\Divers\video_easy_289mb_us_uk.exe
File name: video_easy_289mb_us_uk.exeSize: 330.47 KB (330472 bytes)
MD5: cd336ff7a3501e3906568d22695c4850
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Divers
Group: Malware file
Last Updated: November 11, 2011
%USERPROFILE%\Network\wmpdnc32.exe
File name: wmpdnc32.exeSize: 225.28 KB (225280 bytes)
MD5: d5bc0131009ebf51ec1f7c2b7aee6056
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Network
Group: Malware file
Last Updated: November 18, 2011
%USERPROFILE%\?????????????? ????????\Akey 1.1.2 Rus\akey.1.1.2.exe
File name: akey.1.1.2.exeSize: 2.36 MB (2366658 bytes)
MD5: de9125133d58cd3836d06ae0b9fde3f0
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\?????????????? ????????\Akey 1.1.2 Rus
Group: Malware file
Last Updated: November 4, 2011
Anti-Malware\mfpmp.exe
File name: mfpmp.exeSize: 338.43 KB (338432 bytes)
MD5: 3ff684be5206c79b56d58a75149648ea
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: Anti-Malware
Group: Malware file
Last Updated: December 7, 2011
winmine.exe
File name: winmine.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
route.exe
File name: route.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
rundll32.exe
File name: rundll32.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
qappsrv.exe
File name: qappsrv.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
mem.exe
File name: mem.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
mobsync.exe
File name: mobsync.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
ie4uinit.exe
File name: ie4uinit.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
expand.exe
File name: expand.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
csrss.exe
File name: csrss.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
eventvwr.exe
File name: eventvwr.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.