Sophos

Troj/Roamer-A

Aliases
  • Trojan.Win32.VB.xi
  • W32/Generic.d
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2005 (4.00)
Protection available since 11 September 2005 16:05:29 (GMT)
Last updated 14 October 2005 08:29:09 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Roamer-A is a Trojan for the Windows platform.

When first run Troj/Roamer-A copies itself to:

<Windows>\ActiveX.exe
<System>\Active.exe
<System>\svchost.exe

and creates the following non-malicious files:

\me.bmp
\temp002.txt
<System>\logxp.log

The following registry entries are created to run ActiveX.exe, Active.exe and svchost.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ATITech
<System>\Active.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Roam04
<Windows>\ActiveX.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NortonVPlus
<System>\svchost.exe

The following registry entries are set, affecting internet security:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\<Windows>\system
Active.exe
<System>\Active.exe:*:Enabled:Active

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\<Windows>\system
svchost.exe
<System>\svchost.exe:*:Enabled:svchost

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS
ActiveX.exe
<Windows>\ActiveX.exe:*:Enabled:ActiveX

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer