Home Malware Programs Backdoors Backdoor:Win32/RDPopen

Backdoor:Win32/RDPopen

Posted: January 14, 2013

Threat Metric

Threat Level: 6/10
Infected PCs: 3,715
First Seen: January 14, 2013
Last Seen: January 30, 2023
OS(es) Affected: Windows

Backdoor:Win32/RDPopen is a backdoor Trojan that allows a remote attacker to gain full unauthorized access of the affected computer. Backdoor:Win32/RDPopen creates the connection with an unknown location in order to enable the attacker to perform numerous malicious actions on the infected computer system. The connection can also be used by the attacker to download malicious files leading to more harm on the targeted PC. Once Backdoor:Win32/RDPopen is executed, it will download a copy of malevolent file under various folders and system directories. Backdoor:Win32/RDPopen then creates several registry entries to enable itself to run automatically every time you start Windows. Backdoor:Win32/RDPopen modifies the Windows Registry to avoid Windows Firewall to enable transmission over the existing network. Backdoor:Win32/RDPopen can steal confidential data from victimized computer. Backdoor:Win32/RDPopen also blocks some software on the attacked computer especially if it is security related programs.

Aliases

Trj/Agent.MIZ [Panda]Heuristic.BehavesLike.Win32.ModifiedUPX.C [McAfee-GW-Edition]TR/Ransom.122880.12 [AntiVir]Trojan-Ransom.Win32.Blocker.ajhe [Kaspersky]W32/Kryptik.AB!tr [Fortinet]TR/Cridex.EB.27 [AntiVir]Trojan-Dropper.Win32.Dapato.bnue [Kaspersky]PWS-Zbot.gen.yl [McAfee]Adware/Bromngr [Fortinet]not-a-virus:AdWare.Win32.SuspectCRC [Ikarus]Adware/Win32.Bromngr [AhnLab-V3]Adware.BGuard.7 [DrWeb]BProtector [Sophos]Trj/Genetic.gen [Panda]Generic_r.BRJ [AVG]
More aliases (233)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\BrowserProtect\2.5.986.67\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe File name: BrowserProtect.exe
Size: 2.44 MB (2443800 bytes)
MD5: 3b2ddfabcc929174cd7212d11cef0e0e
Detection count: 1,867
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\BrowserProtect\2.5.986.67\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}
Group: Malware file
Last Updated: July 24, 2021
G:\GAMES\Devil May Cry 3 - SE (Www.ApunKaGames.Net)\Devil May Cry 3 - SE (Www.ApunKaGames.Net)\Game\Mini-Image\asr.exe File name: asr.exe
Size: 45.56 KB (45568 bytes)
MD5: 134e6943f8b7bab9eac7e9400965e50b
Detection count: 295
File type: Executable File
Mime Type: unknown/exe
Path: G:\GAMES\Devil May Cry 3 - SE (Www.ApunKaGames.Net)\Devil May Cry 3 - SE (Www.ApunKaGames.Net)\Game\Mini-Image\asr.exe
Group: Malware file
Last Updated: January 30, 2023
%PROGRAMFILES%\onestep\onestepb.dll File name: onestepb.dll
Size: 861.77 KB (861776 bytes)
MD5: 007c3aca772286dcac7cd0b0831e4c52
Detection count: 72
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\onestep
Group: Malware file
Last Updated: January 16, 2013
D:\Nowy folder\Zrzutek\zrzutek.exe File name: zrzutek.exe
Size: 208.89 KB (208896 bytes)
MD5: eef98640e0e6e4dcee9df1f9bf0677f1
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: D:\Nowy folder\Zrzutek
Group: Malware file
Last Updated: December 29, 2019
%LOCALAPPDATA%\lollipop\yrdwpb.exe File name: yrdwpb.exe
Size: 684.54 KB (684544 bytes)
MD5: 8ac38e96f2cd0305c53cdd8eb398fb3e
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\lollipop
Group: Malware file
Last Updated: January 21, 2013
%ALLUSERSPROFILE%\SOPAgent\sopag_qhxbfwf.exe File name: sopag_qhxbfwf.exe
Size: 131.07 KB (131072 bytes)
MD5: ba6d089d9f19c95318b05032a55a2240
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\SOPAgent
Group: Malware file
Last Updated: January 16, 2013
%USERPROFILE%\Application Data\4EAJQ0M3V4.exe File name: 4EAJQ0M3V4.exe
Size: 16.38 KB (16384 bytes)
MD5: 73c0a0cc3ad07972717854d102c53e43
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: January 16, 2013
%LOCALAPPDATA%\Microsoft\Windows\4449\TURegOpt.exe File name: TURegOpt.exe
Size: 66.56 KB (66560 bytes)
MD5: 1ef30cd92f4f0bf7a7eb40901f255f9e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Microsoft\Windows\4449
Group: Malware file
Last Updated: January 21, 2013
%APPDATA%\Apple\store.exe File name: store.exe
Size: 158.2 KB (158208 bytes)
MD5: 17d5c6d7fbf018bff468d114311bb124
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Apple
Group: Malware file
Last Updated: January 16, 2013
%USERPROFILE%\Start Menu\Programs\Startup\dso4xWsdb.exe File name: dso4xWsdb.exe
Size: 156.67 KB (156672 bytes)
MD5: 3846383ab73e2ef79d9d2cd18f2a376c
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: January 16, 2013
%PROGRAMFILES(x86)%\WindowWizard\WindowWizardT.exe File name: WindowWizardT.exe
Size: 217.08 KB (217088 bytes)
MD5: ecbac4721f2642d8e545ddf9f3b5b055
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\WindowWizard
Group: Malware file
Last Updated: January 16, 2013
9108c2e48ecaa7aad2f557366592cbea File name: 9108c2e48ecaa7aad2f557366592cbea
Size: 78.84 KB (78848 bytes)
MD5: 9108c2e48ecaa7aad2f557366592cbea
Detection count: 5
Group: Malware file
Last Updated: January 15, 2013
%LOCALAPPDATA%\{D878B3E1-877F-81AD-75A9-348E55872013}\syshost.exe File name: syshost.exe
Size: 131.07 KB (131072 bytes)
MD5: 32035abaad7594d5b05646d96221b5e9
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\{D878B3E1-877F-81AD-75A9-348E55872013}
Group: Malware file
Last Updated: January 21, 2013
WKG8CACQ File name: WKG8CACQ
Size: 54.78 KB (54784 bytes)
MD5: 87f9ddaac8810f2c383d4bdfc4031d94
Detection count: 4
Group: Malware file
Last Updated: January 15, 2013
drop/3e61f1aa075715737196f273eb9 File name: drop/3e61f1aa075715737196f273eb9
Size: 79.36 KB (79360 bytes)
MD5: 3e61f1aa075715737196f273eb9c682e
Detection count: 3
Group: Malware file
Last Updated: January 15, 2013
Loading...