Home / malware Backdoor:Win32/Warood.A
First posted on 13 October 2015.
Source: MicrosoftAliases :
There are no other names known for Backdoor:Win32/Warood.A.
Explanation :
Threat behavior
Installation
This threat modifies the registry so that it runs each time you start your PC. For example: In subkey: HKLM\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility\Parameters
Sets value: "ServiceDll"
With data: "%SystemRoot%\installer\~df313.msi"
It can make various registry changes during its installation, including:
In subkey: HKLM\SOFTWARE\Clients\Netrau
Sets value: "HostGuid"
With data: "{afbc62a9-f65a-4736-9298-9c5e62680503}"
Sets value: "InstallTime"
With data: "0x55d7313f"
The malware uses code injection to make it harder to detect and remove. It can inject code into running processes.
Payload
Allows backdoor access and control
This threat can give a malicious hacker access and control of your PC. They can then perform a number of different actions, such as:
- Deleting files
- Downloading and running files
- Logging your keystrokes or stealing your sensitive data
- Modifying your system settings
- Running or stopping applications
- Spreading malware to other PCs
- Uploading files
Connects to a remote host
We have seen this threat connect to a remote host. Malware can connect to a remote host to do any of the following:
- Check for an Internet connection
- Download and run files (including updates or other malware)
- Report a new infection to its author
- Receive configuration or other data
- Receive instructions from a malicious hacker
- Search for your PC location
- Upload information taken from your PC
- Validate a digital certificate
This malware description was published using automated analysis of file SHA1 0f8e8fdaf10fdee17b8ea31cf778add8cececa96.
Symptoms
The following can indicate that you have this threat on your PC:
- You see registry modifications such as:
In subkey: HKLM\SOFTWARE\Clients\Netrau
Sets value: "HostGuid"
With data: "{afbc62a9-f65a-4736-9298-9c5e62680503}"
In subkey: HKLM\SOFTWARE\Clients\Netrau
Sets value: "InstallTime"
With data: "0x55d7313f"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility\Parameters
Sets value: "ServiceDll"
With data: "%SystemRoot%\installer\~df313.msi"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance
Sets value: "First Counter"
With data: "0x00001e2a"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance
Sets value: "First Help"
With data: "0x00001e2b"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance
Sets value: "Last Counter"
With data: "0x00001ed0"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance
Sets value: "Last Help"
With data: "0x00001ed1"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance
Sets value: "Object List"
With data: "7722 7728 7738 7748 7768 7812 7822 7860 7866 7882"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance
Sets value: "PerfIniFile"
With data: "wmiaprpl.ini"
Last update 13 October 2015