Threat Database Backdoors Backdoor.Xtreme.A

Backdoor.Xtreme.A

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 15,845
Threat Level: 60 % (Medium)
Infected Computers: 3,570
First Seen: May 2, 2017
Last Seen: May 22, 2026
OS(es) Affected: Windows

The detection of Backdoor.Xtreme.A on your system indicates a serious security threat that requires immediate attention. This backdoor threat can potentially allow unauthorized access to your computer, compromising your personal data and system security. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Backdoor.Xtreme.A?

Backdoor.Xtreme.A is a type of malware that creates a secret pathway for hackers to access and control your computer remotely. This backdoor can be used to steal sensitive information, install additional malware, or use your system for malicious activities. The presence of Backdoor.Xtreme.A on your system can lead to severe consequences, including data theft, system crashes, and exploitation for cybercrime.

How Backdoor.Xtreme.A Operates

Backdoor.Xtreme.A operates by creating a covert communication channel between your computer and a command and control server controlled by the attacker. This channel allows the attacker to send commands and receive data from your system, effectively giving them remote control over your computer. The backdoor can be installed through various means, including exploited vulnerabilities, drive-by downloads, or social engineering tactics.

Once installed, Backdoor.Xtreme.A can remain dormant, waiting for instructions from the attacker, or it can start executing malicious actions immediately. The backdoor can also attempt to evade detection by using encryption, code obfuscation, or other anti-detection techniques.

Symptoms of Infection

The symptoms of a Backdoor.Xtreme.A infection can be subtle, making it challenging to detect the malware without proper security tools. However, some common indicators of a backdoor infection include unusual network activity, slow system performance, and unexplained changes to system settings or files. You may also notice that your system is behaving erratically, such as crashing or freezing frequently.

  • Unusual network activity, such as unexpected incoming or outgoing connections
  • Slow system performance or responsiveness
  • Unexplained changes to system settings, files, or programs
  • Frequent system crashes or freezes

How to Remove Backdoor.Xtreme.A

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect and remove the backdoor
  3. Uninstall any suspicious programs or applications that may be related to the infection
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings
  5. Reboot your system and perform another full scan to ensure that the backdoor has been completely removed

Conclusion

Removing Backdoor.Xtreme.A from your system requires careful attention to detail and a thorough understanding of the malware's operating characteristics. By following the steps outlined above and using reputable security tools, you can effectively remove the backdoor and prevent future infections. It is essential to remain vigilant and proactive in maintaining your system's security, including keeping your operating system and software up to date, using strong antivirus protection, and being cautious when interacting with unknown or suspicious content.

Analysis Report

General information

Family Name: Backdoor.Xtreme.A
Signature status: No Signature

Known Samples

MD5: e9b7eea56eee10731158115f8bfb71e3
SHA1: f9e1a002f8f53feb300b783fce7d676628e09f7f
SHA256: 887349B7182639235CE6084733B5449132B5CE8CC71D580AF1866FBDBC18C2A6
File Size: 115.71 KB, 115712 bytes
MD5: 83ceb00d1cfaaffec3f654cac4f35001
SHA1: cf2699ce9db33ff6632605f8acb8e45816d9f57d
SHA256: 62C8E848C53CF2032AD9D58CB8A435C9DF5A86BEDCA17970056A4B04C4917DE5
File Size: 115.71 KB, 115712 bytes
MD5: f993bf9672dc129b5c9a8636b189c583
SHA1: 697c0898354987866589829cb7acf4722b4b10ed
SHA256: FC2D1DF1730A50C770B8DAECF6778031B187D46AE00A12E9440AA66EA17B71FF
File Size: 3.27 MB, 3270656 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Microsoft Corporation
Company Name Microsoft Corporation
File Description Microsoft Skype
File Version
  • 15.128.207.0
  • 1.0.0.0
Internal Name
  • Skype
  • skype.exe
Legal Copyright Microsoft Corporation
Legal Trademarks Microsoft Corporation
Original Filename skype.exe
Product Name Microsoft Skype
Product Version
  • 15.128.207.0
  • 1.0.0.0

File Traits

  • HighEntropy
  • No Version Info
  • ntdll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 485
Potentially Malicious Blocks: 78
Whitelisted Blocks: 407
Unknown Blocks: 0

Visual Map

0 0 x x 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 1 0 0 0 0 1 0 0 1 1 2 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 1 1 0 1 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 2 2 2 3 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 2 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x x x 0 0 0 x x 0 x x x x x x 0 x x x x x x x 0 x 0 0 x 0 x 0 x x 0 0 0 x 0 x 0 x x x x 0 x x x 0 0 x x x x x x x 0 x x x x x x x 0 x x x 0 x x 0 0 1 0 x x 0 0 x x 0 0 0 0 0 0 x 0 x x x 0 0 x x 0 x 0 0 x x x 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Xtreme.A

Files Modified

File Attributes
c:\users\user\appdata\local\temp\defender.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\kmspico ativador permanente.exe Generic Write,Read Attributes
c:\users\user\appdata\roaming\windows defender.exe Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鲎ȁ獖} RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �k8 �v����Bx#�(�,��1`1�1HO@V�H[uN$U5�_�z`b.k`k�qo�o�wsU�w�mw�n{b��P��jI��!�����7� ���3�M��~������������T����*�m�Ù��IV�V����$�8�fწ���l��΄�&M�(!��j�@��~� RegNtPreCreateKey
HKCU::di ! RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鲏ȁ獖} RegNtPreCreateKey
HKCU\environment::see_mask_nozonechecks 1 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • OutputDebugString
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecute
  • ShellExecuteEx
User Data Access
  • GetUserObjectInformation

Shell Command Execution

open C:\Users\Frcqfusq\AppData\Local\Temp\DEFENDER.EXE
open C:\Users\Frcqfusq\AppData\Local\Temp\KMSPICO ATIVADOR PERMANENTE.EXE
(NULL) C:\Users\Frcqfusq\AppData\Roaming\windows defender.exe

Related Posts

Trending

Most Viewed

Loading...