Symantec.com > Business > Security Response > Backdoor.Coreflood.C

Backdoor.Coreflood.C

Risk Level 1: Very Low

Printer Friendly Page

Discovered: May 8, 2007
Updated: May 8, 2007 6:21:20 PM
Type: Trojan
Infection Length: 106,496 bytes; 102,400 bytes
Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows NT, Windows Server 2003, Windows 2000

Backdoor.Coreflood.C is a Trojan horse program that opens a back door on the compromised computer and may participate in denial of service attacks.

Variants of Backdoor.Coreflood have been distributed through infected Web pages. Visiting a compromised Web site will cause Backdoor.Coreflood.dr to be downloaded. Backdoor.Coreflood.dr will then attempt to install a Backdoor.Coreflood variant. It has been reported that this may also occur with this variant.

For more information, please review:
Backdoor.Coreflood and Backdoor.Coreflood.dr

Note: Definitions before May 9, 2007 may detect this Trojan as Trojan.Horse.

Protection

  • Initial Rapid Release version May 9, 2007
  • Latest Rapid Release version November 24, 2009 revision 020
  • Initial Daily Certified version May 9, 2007
  • Latest Daily Certified version November 24, 2009 revision 035
  • Initial Weekly Certified release date May 9, 2007

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Moderate

Damage

  • Damage Level: Medium
  • Payload: Opens a back door.
  • Degrades Performance: Participation in denial of service attacks may degrade performance.

Distribution

  • Distribution Level: Low

Writeup By: Liam O Murchu and Piotr Krysiuk
Search by name
Example: W32.Beagle.AG@mm
Windows Vista Security