BKDR_PAPRAS.BQ
Windows 2000, XP, Server 2003
Threat Type: Backdoor
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
BLOCKED:
http://89.187.37.106
http://89.187.53.197
http://27.131.32.21
http://91.213.174.40
This backdoor opens a hidden Internet Explorer window.
It requires its main component to successfully perform its intended routine.
TECHNICAL DETAILS
Varies
DLL
Yes
27 Jul 2010
Compromises system security
Backdoor Routine
This backdoor opens a hidden Internet Explorer window.
It connects to the following URL(s) to send and receive commands from a remote malicious user:
- http://{BLOCKED}.{BLOCKED}.37.106
- http://{BLOCKED}.{BLOCKED}.53.197
- http://{BLOCKED}.{BLOCKED}.32.21
- http://{BLOCKED}.{BLOCKED}.174.40
Other Details
This backdoor requires its main component to successfully perform its intended routine.
SOLUTION
8.900
07.340.15
27 Jul 2010
7/27/2010 12:00:00 AM
6.880.05
27 Feb 2010
7.341.00
27 Jul 2010
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.
Step 2
Scan your computer with your Trend Micro product and note files detected as BKDR_PAPRAS.BQ
Step 3
Restart in Safe Mode
Step 4
Search and delete the file detected as BKDR_PAPRAS.BQ
Did this description help? Tell us how we did.