PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Backdoor

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

Infection Channel: Dropped by other malware

This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may be dropped by other malware.

It connects to certain websites to send and receive information.

  TECHNICAL DETAILS

Memory Resident: Yes
Initial Samples Received Date: 03 Dec 2014
Payload: Connects to URLs/IPs

Arrival Details

This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It may be dropped by the following malware:

  • to allow full scanning of their computers.

Step 2

Note that not all files, folders, and registry keys and entries are installed on your computer during this malware's/spyware's/grayware's execution. This may be due to incomplete installation or other operating system conditions. If you do not find the same files/folders/registry information, please proceed to the next step.

Step 3

Remove the malware/grayware file that dropped/downloaded BKDR_WIPALL.B. (Note: Please skip this step if the threat(s) listed below have already been removed.)

    • If the preceding step requires you to restart in safe mode, you may proceed to edit the system registry.

      RESTORE
    • Close Registry Editor.

Step 6

Restart in normal mode and scan your computer with your live casino online product for files detected as BKDR_WIPALL.B. If the detected files have already been cleaned, deleted, or quarantined by your live casino online product, no further step is required. You may opt to simply delete the quarantined files. Please check this for more information.