Largest Directoty of Internet Security Software

Internet Security Threats

Home Software Threats Security
News
 

Trojan-Proxy.Win32.Agent.v

RISK LEVEL:2



This Trojan launches a proxy server on the victim machine without the knowledgeor consent of the user. It is a Windows PE EXE file. The file is approximately19KB in size. It is packed using PECompact. The unpacked file is approximately50KB in size.

Installation

When launched, the Trojan creates the following folder: %System%\sr64. It then copies its executable file to this folder under a random namewhich is made up of numbers and an .exe extension.

The Trojan also adds a link to its executable file in the system registry,ensuring that the Trojan will be launched when Windows is rebooted on the victimmachine:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"sr64" = "<path and name of Trojan executable file>"

The Trojan also extracts the following file from its body:

  • %System%\sr64\sr32.dll — this file is 7,168 bytes in size. It will be detected by KasperskyAnti-Virus as Trojan-Proxy.Win32.Agent.x

The Trojan launches an HTTP proxy server on TCP port 1185 and a SOCKS proxyservier on TCP port 1186.

It then sends the version of the operating system, the IP address of the victimmachine, and the numbers of open ports to the remote malicious user's site.

If your computer does not have an up-to-date antivirus, or does not have anantivirus solution at all, follow the instructions below to delete the maliciousprogram:

  1. Use Task Manager to terminate the Trojan process
  2. Delete the following folder and its contents:
    %System%\sr64
  3. Delete the following system registry key parameter:
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "sr64" = "<path and name of Trojan executable file>"
  4. Update your antivirus databases and perform a full scan of thecomputer (download a trial version of Kaspersky Anti-Virus).


Printed From:http://www.viruslist.com/en/viruses/encyclopedia?virusid=41040


Similar Virus/Threat >>
  •   Trojan-Proxy.Win32.Agent.o
  • This Trojan launches a proxy server on the victim machine without the knowledgeor consent of the user. It is a Windows PE EXE file. It is 139,264 bytes insize. It is not packed in any way. It is...
  •   Trojan-Proxy.Win32.Agent.q
  • This Trojan launches a proxy server on the victim machine without the knowledgeor consent of the user. It is a Windows PE EXE file. The file is 28,796 bytesin size. It is not packed in any...
  •   Trojan-Proxy.Win32.Daemonize.a
  • This Trojan launches a proxy server on the victim machine without the user'sknowledge or consent. This makes it possible for a remote malicious user toappear as though his actions are being carried...
  •   Trojan-Proxy.Win32.Mitglieder.o
  • This Trojan launches a proxy mail server on the victim machine. It is a WindowsDLL file. It is 27,136 bytes in size. InstallationThis Trojan will be installed to the victim machine by another...
  •   Trojan-Proxy.Win32.Agent.x
  • This Trojan launches a proxy server on the victim machine without the knowledgeor consent of the user. It is a Windows PE EXE file. The file is approximately17KB in size. It is packed using...
  •   Trojan-Proxy.Win32.Xorpix.v
  • This Trojan program makes it possible for a remote malicious user to use thevictim machine as a proxy server. It is a Windows PE EXE file. The file isapproximately 15KB in size. It is written in...
  •   Trojan-Proxy.Win32.Xorpix.ar
  • This Trojan program makes it possible for a remote malicious user to use thevictim machine as a proxy server. It is a Windows PE EXE file. The file isapproximately 17KB in size. It is packed...


  • Window Washer
  • symantec PCanywhere 12.0
  • Kaspersky Anti-Hacker
  • iSpyNOW
  • Diet Kaza

  • Acronis Privacy Expert Suite 8.0
    (31,781KB - $29.99)
    AIM Spy Monitor 2007
    (3,145KB - $39.99)
    BlazingTools Secure Office
    (1,301KB - $54.95)
    Yahoo! Messenger Spy Monitor 2007
    (4,034KB - $39.99)
    Encrypt my Folder
    (1,530KB - $24.95)

    Cookie Cleaner   |    History Eraser   |    Popup Killer   |   Firewall   |   Antivirus   |   Security Encryption   |   UnInstaller   |   Security News
    eTrust Pestpatrol Anti-Spyware   PestPatrol 5   Ad-Aware SE Removal   Ad-Aware SE   Ad-Watch   SpyFighter Cleaner Pro   Free Adware Remover   Spy Sweeper  Webroot Spy Sweeper 
    Copyright © 2002-2007 Internet Security Software.All rights reserved.
    Directory of Internet Security Software - Cookie & Cache Cleaner, History & Evidence Eraser, Popup Killer, Firewall