TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
BKDR_OPTIXPRO.12
Overview

Malware type: Backdoor

Aliases: Backdoor.Win32.Optix.Pro.10 (Kaspersky), Backdoor.OptixPro.13 (Symantec), BDS/Optix.Gen (Avira), Troj/OptixPr-12 (Sophos),

In the wild: No

Destructive: Yes

Language: English

Platform: Windows 95, 98, ME, NT, 2000 and XP

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Description: 

This backdoor malware has a server program that infects target systems and a client program that is used to access and manipulate the infected system. It also has a server editor program that enables a an attacker to modify server settings.

Upon execution, it displays an error message that varies, depending on the configurations that was set by the malicious user. An example is shown below:

BKDR_OPTIXPRO.12 displays an error message with the title Error and message General Protection Fault at address 0x00000009

This malware compromises network security by allowing malicious users to connect to a port and gain unauthorized access to a remote system. The malicious user can do the following to the compromised system:

  • Switch the monitor on and off
  • Open or close the CD-ROM drive
  • Play media files
  • Print text
  • Change desktop wallpaper
  • Hide icons, buttons, the system tray, and the taskbar
  • Install an FTP server
  • Download and execute files

It runs on Windows 95, 98, ME, NT, 2000, and XP.

For additional information about this threat, see:
Solution
Technical Details

Description created: Oct. 10, 2002 6:56:50 PM GMT -0800
Description updated: Mar. 29, 2005 9:54:55 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.