Threat Profile: RemoteAdmin.svr

Threat Search
Print
   
Virus Profile information details
Risk Assessment: Home N/A | Corporate N/A
Date Discovered: 1/10/2001
Date Added: 4/11/2003
Origin: Unknown
Length: Varies
Type: Program
Subtype: Remote Access
DAT Required: 4118
Removal Instructions
   
 
 
   

Description

This is a Potentially Unwanted Program (PUP) detection. It is not a virus or trojan. PUPs are any piece of software which a reasonably security-or privacy-minded computer user may want to be informed of.

Symptoms

N/A  This is not a virus or trojan.

Method

N/A

Aliases

RemAdm-RemoteAdmin.dll
   

Virus Characteristics

McAfee(R) AVERT™ recognizes that this program may have legitimate uses in contexts where an authorized administrator has knowingly installed this application. If you agreed to a license agreement for this, or another bundled application, you may have legal obligations with regard to removing this software, or using the host application without this software. Please contact the software vendor for further information.

See http://vil.nai.com/vil/DATReadme.asp for a list of Program detections added to the DATs.

See http://vil.nai.com/vil/pups/configuration.htm for information about how to enable, disable, and exclude detection of legitimately installed programs.

RemoteAdmin is a remote control program provided by Famatech http://www.famatech.com/ .  This tool is made up of a client and a server component.  The server component runs as a service on the remote XP/2000 computer. The service name can be "Remote Administrator service". Once the service is running, an administrator using a client program can view activity, take control, transfer files, and shutdown the remote system.

This application may have been installed by your system administrator for providing support for your machine. If this is the case then the alert on this detection should be ignored and may be excluded as described here:
http://vil.nai.com/vil/pups/configuration.htm

However, this application has been abused by several trojan authors for malicious purposes.

The server component of this applications listens on TCP port 4899 by default.

The following registry entry may be associated with this program:

  • HKEY_CURRENT_USER\Software\RAdmin