Sophos

Troj/RtKit-11

Aliases
  • BKDR_TIKTR.A
Category
Type
What to do
Prevalence low high

Summary

 
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing Trojans.

Delete any non-Trojan dropped files you do not want

More Information

Troj/RtKit-11 is a backdoor Trojan that allows a remote attacker to control various aspects of an affected computer's operation. When run the Trojan will create the following files in the RtKit subfolder of the Windows system folder:

rtkit.exe
globalc.dll
npf.sys
ntcs.dll
packet.dll

Npf.sys, ntcs.dll and packet.dll are legitimate network utilities. Rtkit.exe is a copy of the Trojan and globalc.dll is a component of the Trojan.

Troj/RtKit-11 will also install rtkit.exe and npf.sys as services that are set to automatically start when Windows starts.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer