Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 28 March 2005 16:00:41 (GMT) |
| Last updated | 28 March 2005 17:18:26 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Riler-F is a backdoor Trojan.
Troj/Riler-F provides a remote command shell which allows an attacker to run arbitrary commands on the infected system.
Troj/Riler-F copies itself to the Windows system folder as FLASHMGR.EXE and registers this copy as the service process "Flash Memory" with display name "Flash Memory tool".
Troj/Riler-F drops a component of itself as MSNORTH.DLL in the Windows system folder. The Trojan may arrive as a CHM file which drops the main Trojan as COO#KIE.EXE. The CHM and DLL files are also detected as Troj/Riler-F. The CHM file also contains an HTML script that is detected as Troj/Riler-E.
Troj/Riler-F may attempt to inject code into other running processes.
