TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TSPY_PAPRAS.AD
Overview

QUICK LINKS  

Download the latest scan engine


TypeSpyware

In the wild: No

Destructive: No

Language: English

Systems affected: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:

Low

Reported detections:

Low

System  impact:

High

Information exposure:

High

 

Description:

To get a one-glance comprehensive view of the behavior of this spyware, refer to the Behavior Diagram shown below.

TSPY_PAPRAS.AD Behavior Diagram

Spyware Overview

This spyware arrives as attachment to email messages spammed by another malware or a malicious user. It may be downloaded from remote site(s) by other malware. It may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web site(s).

It drops a copy of itself, a non-malicious batch file and a file detected by Trend Micro as TROJ_AGENT.CWT.

It terminates the initially executed copy and executes the dropped copy. It also executes the dropped file. As a result, malicious routines of the dropped file are exhibited on the affected system.

This spyware creates a registry entry to enable its automatic execution at every system startup. It also creates registry keys and modifies a certain registry entry as part of its installation routine.

It gathers information by searching for certain Protected Storage items. It sends the gathered information to several URLs using HTTP post. This routine risks the exposure of the sensitive information, which may then lead to the unauthorized use of the stolen data.

It also creates a mutex to ensure that only one instance of itself is running in memory. It deletes itself after execution. It also deletes files found in a certain folder under the current user's profile folder.

For additional information about this threat, see:
Solution
Technical Details

Description created: Apr 29, 2008




Tell us how we did. Take our quick survey.