Home Malware Programs Backdoors Backdoor.Wakeminap

Backdoor.Wakeminap

Posted: June 5, 2012

Threat Metric

Threat Level: 6/10
Infected PCs: 83
First Seen: June 5, 2012
OS(es) Affected: Windows

Backdoor.Wakeminap is a backdoor Trojan that opens a back door on the infected computer. Once executed, Backdoor.Wakeminap downloads malicious files. Backdoor.Wakeminap also downloads a safe file with a .doc, .pdf, or .ppt extension under the %Temp% or %CurrentFolder% directory and then opens it. Backdoor.Wakeminap may copy itself as the certain file. Backdoor.Wakeminap then creates the certain registry entry so that it can run automatically every time you start Windows. Backdoor.Wakeminap opens a back door by connecting to the particular locations and awaits instructions from the remote attacker. The remote attacker is able to list running processes and stop processes.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.zip File name: file.zip
Size: 507.31 KB (507315 bytes)
MD5: 4fa2548d9bac5fa4d67d304b8fc49277
Detection count: 19
Mime Type: unknown/zip
Group: Malware file
Last Updated: June 7, 2012
DuPont.exe File name: DuPont.exe
Size: 570.17 KB (570175 bytes)
MD5: 281c5a691a4db4397e1152eb32151a4c
Detection count: 18
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 7, 2012
file.zip File name: file.zip
Size: 104.73 KB (104735 bytes)
MD5: 7492cb9df6fcd574d14074cd822aac1b
Detection count: 17
Mime Type: unknown/zip
Group: Malware file
Last Updated: June 7, 2012
FR-Criteria4-12.zip File name: FR-Criteria4-12.zip
Size: 104.74 KB (104741 bytes)
MD5: 4d42b40bd56a7713eb20a6268c3a21da
Detection count: 16
Mime Type: unknown/zip
Group: Malware file
Last Updated: June 7, 2012
C:\Recycler\[RANDOM NUMBER].tmp File name: C:\Recycler\[RANDOM NUMBER].tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
%Temp%\AdobeUpdate.exe File name: %Temp%\AdobeUpdate.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\AdobeUpdater.exe File name: %Temp%\AdobeUpdater.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\qttask.exe File name: %Temp%\qttask.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\smss.exe File name: %Temp%\smss.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Adobe Update" = "[PATH TO DROPPED FILE]"
Loading...