BKDR_PERLBOT.SMM
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Backdoor
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This backdoor may be downloaded by other malware/grayware/spyware from remote sites. It may be unknowingly downloaded by a user while visiting malicious websites.
TECHNICAL DETAILS
29601 bytes
Other
No
16 Sep 2010
Compromises system security
Arrival Details
This backdoor may be downloaded by other malware/grayware/spyware from remote sites.
It may be unknowingly downloaded by a user while visiting malicious websites.
NOTES:
This is Trend Micro's detection for backdoor trojans written using Perl Script. It connects to a remote IRC server to listen and wait for commands coming from a malicious user. Once successfully connected, it can perform a number of routines including:
- Upload/Download files
- Execute files
- Denial of Service attack
SOLUTION
8.900
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.
Step 2
Search and delete the file detected as BKDR_PERLBOT.SMM
Did this description help? Tell us how we did.