Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2005 (4.00) |
| Protection available since | 11 September 2005 16:05:29 (GMT) |
| Last updated | 14 October 2005 08:29:09 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Roamer-A is a Trojan for the Windows platform.
When first run Troj/Roamer-A copies itself to:
<Windows>\ActiveX.exe
<System>\Active.exe
<System>\svchost.exe
and creates the following non-malicious files:
\me.bmp
\temp002.txt
<System>\logxp.log
The following registry entries are created to run ActiveX.exe, Active.exe and svchost.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ATITech
<System>\Active.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Roam04
<Windows>\ActiveX.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NortonVPlus
<System>\svchost.exe
The following registry entries are set, affecting internet security:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\<Windows>\system
Active.exe
<System>\Active.exe:*:Enabled:Active
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\<Windows>\system
svchost.exe
<System>\svchost.exe:*:Enabled:svchost
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS
ActiveX.exe
<Windows>\ActiveX.exe:*:Enabled:ActiveX
