Home Malware Programs Backdoors Backdoor.Wisti

Backdoor.Wisti

Posted: September 19, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 7
First Seen: September 19, 2012
Last Seen: October 8, 2022
OS(es) Affected: Windows

Backdoor.Wisti is a backdoor Trojan that opens a back door on the infected computer. Backdoor.Wisti usually spreads via malicious PDF files. Once executed, Backdoor.Wisti can create malicious files and modify the Windows Registry. Backdoor.Wisti may connect to numerous URLs. Backdoor.Wisti connects to a command-and-control (C&C) server in order to receive instructions from attackers. Backdoor.Wisti allows attackers to collect computer system and PC user's information and retrieve Internet Explorer and Firefox configuration data.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Temp%\lass.exe File name: %Temp%\lass.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\csrss.exe File name: %Temp%\csrss.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\svchost.exe File name: %Temp%\svchost.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Windir%\~00ELISE1D797.TMP File name: %Windir%\~00ELISE1D797.TMP
File type: Temporary File
Mime Type: unknown/TMP
Group: Malware file
%UserProfile%\Application Data\Microsoft\Network\msscrt726.dll File name: %UserProfile%\Application Data\Microsoft\Network\msscrt726.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc

Additional Information

The following URL's were detected:
nicyaboyenan.com
Loading...