Radmin – a dangerous trojan horse that allows bad actors to remotely control your device

Radmin virus is a remote administration tool (RAT) that comes into systems as a trojan horse[1] via spam emails or malicious websites. The malware gains root access to the computer and allows hackers to remotely control it, like making screenshots or installing another malware. Unfortunately, the main executable deletes itself as soon as the malicious payload is executed, making detection and removal much more complicated.
| SUMMARY | |
| Name | Radmin |
| Type | Trojan Horse |
| Distribution | Spam emails, malicious websites |
| Symptoms | Rarely any, although users may notice occasional freezes or/and crashes |
| Main dangers | Stolen personal information and malware infiltration |
| Detection and elimination | Use FortectIntego |
Initially, this software is an official tool used by IT specialists as administration software. However, the remote access component can be abused by hackers to control victims' computers, which gets injected via a trojan. We are going to talk about the malicious version of the program, namely, Radmin virus or Win32.RAdmin.Zenworks.
Remote administration tools are hazardous when abused by cybercriminals, because users may completely lose the control of their machine. As soon as the malware is injected into the PC, it creates the following files:
-
C:\Windows\System32\config\admdll.dll
-
C:\Windows\System32\config\raddrv.dll
-
C:\Windows\System32\config\svchost.exe
-
C:\Windows\System32\config\svcset.bat
-
C:\Windows\System32\config\svcset.reg
-
C:\:services.exe
System services, used by Windows OS are replaced by malicious executable which runs in the Task Manager. Malware also modifies other settings in order to gain persistence. There is no doubt that users should immediately remove Radmin trojan from their computers, and it should not be done manually, as trojan horses are viruses that are written in a sophisticated code. Therefore, we suggest using security software, such as FortectIntego.
The RAT tool allows hackers to perform various malicious tasks on the targeted computer, including:
- Multiply itself via the network;
- Download and upload malicious files;
- Change various system parameters;
- Start or shut down applications;
- Record victim's activity.
Although some files might be deleted or software corrupted, it is not the main danger of Radmin trojan. Information tracking can lead to severe consequences, such as identity theft[2] or stolen money directly from your bank account.
Unfortunately, the malware rarely exposes any symptoms, as its goal is to remain undetected while the malicious activity is taking place. However, users may experience occasion system or software crashes or freezes, increased CPU usage, an increased amount of advertisement on their browsers, and an overall sluggish PC performance.
Therefore, we advise you take care of Radmin removal. For that, you will have to scan your machine with reputable security software.

Malware can strike unexpectedly, so be ready
Trojan horses are the sneaky type of infections which also opens doors to other malware, such as ransomware or digital currency miners. These cyber threats are perilous as they can lead to file destruction or hardware wear and tear over time. Of course, there is no way to protect yourself from malware 100%, but there is something you can do to decrease the possibility of infection.
Security experts[3] note that the most effective trojan horse distribution method is via malicious spam email attachments. With the help of bots, hackers send out thousands of emails to various users. These phishing emails may look dodgy, or closely resemble/look identical to messages one would get from the legitimate company, like Amazon or FedEx.
Therefore, it is essential to recognize these threats. Never open attachments within these emails, especially if they ask for the macro function to be enabled. Additionally, pay attention to hyperlinks that are fake – merely place a cursor on it and you will see the address it will lead you to. Finally, check the “From” address – it is the biggest giveaway that it is a scam.
If your computer is infected with RadMin virus, proceed with the following elimination steps
To remove Radmin virus, you will have to download and install security software, if you do not possess one yet. We recommend using FortectIntego or MalwarebytesMalwarebytes, as these products are leaders in cybersecurity market and can take care of even the toughest virus.
Beware that the trojan deletes its executable and can make detection much more complicated. To ensure complete Radmin removal, we suggest you enter Safe Mode with Networking on your device, as explained below.
Did this guide help?
Be the first to comment