Threat Database Backdoors Backdoor.Revird

Backdoor.Revird

By Domesticus in Backdoors

Backdoor.Revird is a backdoor Trojan that opens a back door on the compromised PC and aims at stealing sensitive information. When executed, Backdoor.Revird creates potentially malicious files. Backdoor.Revird registers the file '%System%\nwwwsk.dll' as a new service with the particular characteristics, so that it can run automatically every time Windows is started. Backdoor.Revird creates the service by adding entries to the registry subkey. Backdoor.Revird opens a back door on the affected computer, which allows a remote attacker to perform malicious actions that include downloading, uploading, deleting and executing files, and listing, stopping, and starting processes and services. Backdoor.Revird collects information of the attacked PC. Backdoor.Revird copies all files with the extensions such as .pdf, .ppt, .doc, .zip and .rar to the particular folder and transmits them to a predetermined remote location.

File System Details

Backdoor.Revird may create the following file(s):
# File Name Detections
1. %System%\rdisk.dll
2. %System%\skeys.dll
3. %System%\nwwwks.dll
4. %System%\SvcHost.DLL.exe
5. %System%\SvcHost.DLL.log

Registry Details

Backdoor.Revird may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NWCworkstation

Trending

Most Viewed

Loading...