Backdoor.RefpronIn other words, Backdoor.Refpron is an example of a remote administration utility that was designed to open up exploits on an infected system, so as to allow for external control of the machine, via LAN or via the internet itself. The difference between legitimate remote administrative utilities and Backdoor.Refpron is the fact that Backdoor.Refpron launches and installs backdoors into the system without the user’s knowledge or permission thereof, therefore the infected system is covertly infiltrated and remains covertly active regardless. As a Backdoor infection, Backdoor.Refpron may be capable of performing the following functions: • Add registry files • Download unsolicited files • Obtain file version information • Listen on a specific port, to retrieve files and other data In order to safeguard a computer system against these type of backdoor infections, there are a few steps one can take to ensure the safety of a computer system: 1. Use a firewall to block all dubious connections from the internet. 2. Enforce a password policy. Ensure the passwords implemented are complex, so as to prevent and limit damage to a compromised system. 3. Ensure that programs and users are at its lowest level of privileges – this way access is limited to the administrator. 4. Disable AutoPlay – this way you prevent the automatic launching of executable files on networks and removal drives. 5. Turn off File Sharing if it is not needed. 6. Turn off and remove all unnecessary services. 7. Always keep patch-levels up-to-date 8. Configure your server to block and remove all email attachments that have the file extensions: .vbs, .bat, .exe, .pif, .scr – as these type files are usually affiliated with malicious applications. 9. So, how would one remove this dubious infection from a computer system? IT experts are of the opinion that manual removal of Backdoor.Refpron is not the best solution, as the manual removal process is rather complicated and cumbersome, and should not be attempted by someone that is not familiar with the registry files of a computer system. The best way to ensure your system is safe, and in order to avoid any unneeded risks of damage to your computer system, it is highly recommended to make use of a reliable and legitimate anti-spyware application, to remove Backdoor.Refpron and all its components from the infected computer system. |
|
|
Danger level:
8
8
Type: Trojan
Common infection symptoms:
- Installs itself without permissions
- Connects to the internet without permision
- Slow internet connection
- Slow Computer
How to manually remove Backdoor.Refpron
Files associated with Backdoor.Refpron infection:
sopidkc.exe
wtukd32.exe
tpszxyd.sys
perfs.exe
mabidwe.exe
afisicx.exe
wtukd32.exe
tpszxyd.sys
perfs.exe
mabidwe.exe
afisicx.exe
Backdoor.Refpron processes to kill:
sopidkc.exe
wtukd32.exe
perfs.exe
mabidwe.exe
afisicx.exe
wtukd32.exe
perfs.exe
mabidwe.exe
afisicx.exe
Remove Backdoor.Refpron registry entries:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sopidkc
RUNNING PROGRAM\tpszxyd.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Network Connections Logs
RUNNING PROGRAM\mabidwe.exe
RUNNING PROGRAM\sopidkc.exe
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\afisicx
RUNNING PROGRAM\tpszxyd.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Network Connections Logs
RUNNING PROGRAM\mabidwe.exe
RUNNING PROGRAM\sopidkc.exe
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\afisicx

Comments
Very informative. Thank you!