Sophos

Troj/Remadm-C

Aliases
  • Win32.HLLP.Shodi.d
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 31 October 2004 13:48:08 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

On execution Troj/Remadm-C copies itself to the Windows system
folder with the filename Virt.exe and then attempts to drop the following
files to the Windows system folder:

AdmDll.dll
MyVirt.exe

Both of which are legitimate applications.

Troj/Remadm-C creates the following registry entries with the paths
to the Virt.exe and MyVirt.exe files correspondingly:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Virt.exe =
%system%\Virt.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MyVirt.exe =
%system%\MyVirt.exe /port:7351 /pass:xxxx

(Password is blanked out in this description)

Troj/Remadm-C also attempts to install configurations in registry entry
HKLM\SYSTEM\radmin\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer