Threat Database Backdoors Backdoor.Win32.Cakl.ba

Backdoor.Win32.Cakl.ba

By GoldSparrow in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 3
First Seen: September 9, 2011
Last Seen: November 19, 2018
OS(es) Affected: Windows

Backdoor.Win32.Cakl.ba is a mischievous backdoor Trojan which is surreptitiously installed by other malware threats and may corrupt your computer settings and redirect you to malicious websites that hosts the installation files of the rogue security applications. Backdoor.Win32.Cakl.ba runs in the background and enables attackers to gain remote access to an affected machine. Backdoor.Win32.Cakl.ba can steal your personal information and forward it to remote attackers for malicious purpose. Get rid of Backdoor.Win32.Cakl.ba as quickly as possible.

File System Details

Backdoor.Win32.Cakl.ba may create the following file(s):
# File Name Detections
1. %System%\cuntrag32.exe
2. %System%\ntswrl32.dll
3. %Temp%\IXP000.TMP\test.exe
4. %System%\ntcvx32.dll
5. %System%\ldapi32.exe

Registry Details

Backdoor.Win32.Cakl.ba may create the following registry entry or registry entries:
Regexp file mask
%WINDIR%\SysWOW64\vssms32.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\dmio.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\EventLog
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\HelpSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\Base
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\CryptSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\dmboot.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\dmserver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\Filter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\AppMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\Boot file system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\dmadmin
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\dmload.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\File system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\Boot Bus Extender
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\minimal.xxx\DcomLaunch

Trending

Most Viewed

Loading...