Sophos

Troj/Riler-F

Aliases
  • BackDoor-BCB
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 28 March 2005 16:00:41 (GMT)
Last updated 28 March 2005 17:18:26 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Riler-F is a backdoor Trojan.

Troj/Riler-F provides a remote command shell which allows an attacker to run arbitrary commands on the infected system.

Troj/Riler-F copies itself to the Windows system folder as FLASHMGR.EXE and registers this copy as the service process "Flash Memory" with display name "Flash Memory tool".

Troj/Riler-F drops a component of itself as MSNORTH.DLL in the Windows system folder. The Trojan may arrive as a CHM file which drops the main Trojan as COO#KIE.EXE. The CHM and DLL files are also detected as Troj/Riler-F. The CHM file also contains an HTML script that is detected as Troj/Riler-E.

Troj/Riler-F may attempt to inject code into other running processes.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer