Home Malware Programs Backdoors Backdoor:Win32/Caphaw.A

Backdoor:Win32/Caphaw.A

Posted: November 18, 2011

Threat Metric

Threat Level: 6/10
Infected PCs: 70
First Seen: November 1, 2011
Last Seen: April 6, 2020
OS(es) Affected: Windows

Backdoor:Win32/Caphaw.A is a malicious firewall-bypassing backdoor Trojan that propagates via status updates on Facebook. Backdoor.Win32.Caphaw.A targets the Windows platform and allows attackers to gain remote access to the infected PCs. Backdoor:Win32/Caphaw.A can block URL requests in both Firefox and Internet Explorer and is able to post very personable updates on friends' walls in Facebook, obtaining access if the PC user is logged in. The posted message redirects to a video posted on a website similar to Youtube, which offers the user to update the browser with a fake ActiveX object. The video landing page seems to be a legitimate one. The particular download is, in fact, Backdoor:Win32/Caphaw.A, which installs an FTP server, a proxy server, and a keylogger on the targeted computer. Backdoor:Win32/Caphaw. also has a built-in remote desktop functionality based on the open source VNC project. Backdoor:Win32/Caphaw is also known to be able compromise bank accounts and steal money because of the keylogging component, associated with the remote desktop functionality; that's why Backdoor:Win32/Caphaw.A is considered to be an online identity threat. Find a reliable and trustworthy anti-malware tool to uninstall Backdoor:Win32/Caphaw form the infected PC system.

Aliases

Trj/CI.A [Panda]Dropper.Generic4.CHTA [AVG]W32/BackDoor.DV3!tr [Fortinet]Backdoor.Win32.Caphaw [Ikarus]Trojan/Win32.HDC [AhnLab-V3]Mal/Generic-L [Sophos]BDS/Caphaw.A.102 [AntiVir]Trojan.DownLoader5.17344 [DrWeb]UnclassifiedMalware [Comodo]Trojan.Generic.6948249 [BitDefender]Trojan-Dropper.Win32.Injector.zee [Kaspersky]Win32:Rootkit-gen [Rtk] [Avast]Trojan.Gen [Symantec]a variant of Win32/Kryptik.VYC [NOD32]Riskware [K7AntiVirus]
More aliases (63)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Ulead Systems\Ulead VideoStudio\netiougc.exe File name: netiougc.exe
Size: 340.44 KB (340440 bytes)
MD5: 2de054cf7b8f3dab89d6b9cef13f335a
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Ulead Systems\Ulead VideoStudio
Group: Malware file
Last Updated: November 1, 2011
%PROGRAMFILES%\Divers\video_easy_289mb_us_uk.exe File name: video_easy_289mb_us_uk.exe
Size: 330.47 KB (330472 bytes)
MD5: cd336ff7a3501e3906568d22695c4850
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Divers
Group: Malware file
Last Updated: November 11, 2011
%USERPROFILE%\Network\wmpdnc32.exe File name: wmpdnc32.exe
Size: 225.28 KB (225280 bytes)
MD5: d5bc0131009ebf51ec1f7c2b7aee6056
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Network
Group: Malware file
Last Updated: November 18, 2011
%USERPROFILE%\?????????????? ????????\Akey 1.1.2 Rus\akey.1.1.2.exe File name: akey.1.1.2.exe
Size: 2.36 MB (2366658 bytes)
MD5: de9125133d58cd3836d06ae0b9fde3f0
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\?????????????? ????????\Akey 1.1.2 Rus
Group: Malware file
Last Updated: November 4, 2011
Anti-Malware\mfpmp.exe File name: mfpmp.exe
Size: 338.43 KB (338432 bytes)
MD5: 3ff684be5206c79b56d58a75149648ea
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: Anti-Malware
Group: Malware file
Last Updated: December 7, 2011
winmine.exe File name: winmine.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
route.exe File name: route.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
rundll32.exe File name: rundll32.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
qappsrv.exe File name: qappsrv.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
mem.exe File name: mem.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
mobsync.exe File name: mobsync.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
ie4uinit.exe File name: ie4uinit.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
expand.exe File name: expand.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
csrss.exe File name: csrss.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
eventvwr.exe File name: eventvwr.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Loading...