I forgot to mention another part also written in the Easynews article:
The virus also installs radmin (radmin.com) running as 'r_server'. From the radmin.com site, "With Radmin you can work on a remote computer exactly as if you were right there at its keyboard."
My Kaspersky AV detected the virus after a signature update and identified it as Exploit.Win32.MS04-028.gen.
|