Backdoor:Win32/Vawtrak.A Description

Type: Backdoors

Backdoor:Win32/Vawtrak.A is a backdoor Trojan that enables cybercriminals to obtain full remote access and control of the compromised PC. Backdoor:Win32/Vawtrak.A can also steal information such as login information if a victimized computer user visits particular banking websites. Backdoor:Win32/Vawtrak.A is used by fraudsters to take over personal financial information of the attacked PC user. Backdoor:Win32/Vawtrak.A aims at stealing private details and personal information from the target web user to carry out a fraud. Backdoor:Win32/Vawtrak.A may steal the victim's information by recording usernames and passwords. Backdoor:Win32/Vawtrak.A may make continuous changes to the corrupted PC's configuration that cannot be restored by finding and uninstalling this malware infection.

Technical Information

File System Details

Backdoor:Win32/Vawtrak.A creates the following file(s):
# File Name MD5 Detection Count
1 JubuJujf.nvk 6b4f8858ba6759aaa5e80a2e540a0566 4
2 ejrtzpaz.dat N/A
3 uvfuvwog.dat N/A
4 zlbgqk.dat N/A
5 degwbxm.dat N/A
6 iopwark.dat N/A
7 xausgo.dat N/A
8 dqxcovwm.dat N/A
9 fvvifvwz.dat N/A
10 wthejcy.dat N/A
11 file.exe b831b18b9767071930691ae98d4f3b77 0

Registry Details

Backdoor:Win32/Vawtrak.A creates the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[DLL file name]" = "regsvr32.exe /s "%ALLUSERSPROFILE%\AppData\[DLL file name].dat""
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "TabProcGrowth" = "dword:00000000"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "bqbclrtr" = "regsvr32.exe /s "C:\Documents and Settings\All Users\Application Data\bqbclrtr.dat""
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "NoProtectedModeBanner" = "dword:00000001"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 "2500" = "dword:00000003"

Site Disclaimer is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.