Sophos

Troj/Vivia-C

Aliases
  • Trojan.Win32.Agent.ah
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 28 January 2005 13:44:49 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Vivia-C is a backdoor Trojan.

Troj/Vivia-C copies itself to a randomly-named subfolder of the Windows system folder with a random filename with an EXE extension. Troj/Vivia-C then sets an entry in the registry at the following location with a value name the same as the filename:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\

Troj/Vivia-C adds entries in the registry at the following location to reference itself:

HKCR\CLSID\[random CLSID]

Troj/Vivia-C modifies the following registry entry:

HKCU\Software\Microsoft\Internet Explorer\Main\
NID

Troj/Vivia-C attempts to contact the site http:\\aug.lzio.com to send information about the infected computer.

Troj/Vivia-C may attempt to modify the HOSTS file to prevent access to certain websites.

Troj/Vivia-C attempts to terminate a number of anti-virus and security-related processes.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer