Analysis by: adel

 PLATFORM:

Windows 98, ME, NT, 2000, XP, Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Backdoor

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This backdoor has received attention from independent media sources and/or other security firms.

To get a one-glance comprehensive view of the behavior of this Backdoor, refer to the Threat Diagram shown below.

  SOLUTION

Minimum Scan Engine: 8.900
VSAPI OPR PATTERN File: 6.950.05
VSAPI OPR PATTERN Date: 25 Mar 2010

Step 1

For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.

Step 2

Remove malware files dropped/downloaded by BKDR_RIPINIP.I

    ?