This Trojan launches a proxy server on the victim machine without the knowledgeor consent of the user. It is a Windows PE EXE file. The file is approximately19KB in size. It is packed using PECompact. The unpacked file is approximately50KB in size. InstallationWhen launched, the Trojan creates the following folder: %System%\sr64. It then copies its executable file to this folder under a random namewhich is made up of numbers and an .exe extension. The Trojan also adds a link to its executable file in the system registry,ensuring that the Trojan will be launched when Windows is rebooted on the victimmachine: [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]"sr64" = "<path and name of Trojan executable file>" The Trojan also extracts the following file from its body: - %System%\sr64\sr32.dll — this file is 7,168 bytes in size. It will be detected by KasperskyAnti-Virus as Trojan-Proxy.Win32.Agent.x
The Trojan launches an HTTP proxy server on TCP port 1185 and a SOCKS proxyservier on TCP port 1186. It then sends the version of the operating system, the IP address of the victimmachine, and the numbers of open ports to the remote malicious user's site. If your computer does not have an up-to-date antivirus, or does not have anantivirus solution at all, follow the instructions below to delete the maliciousprogram: - Use Task Manager to terminate the Trojan process
- Delete the following folder and its contents:
%System%\sr64 - Delete the following system registry key parameter:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "sr64" = "<path and name of Trojan executable file>" - Update your antivirus databases and perform a full scan of thecomputer (download a trial version of Kaspersky Anti-Virus).
Printed From:http://www.viruslist.com/en/viruses/encyclopedia?virusid=41040
Similar Virus/Threat >>
Trojan-Proxy.Win32.Agent.o
This Trojan launches a proxy server on the victim machine without the knowledgeor consent of the user. It is a Windows PE EXE file. It is 139,264 bytes insize. It is not packed in any way. It is...
Trojan-Proxy.Win32.Agent.q
This Trojan launches a proxy server on the victim machine without the knowledgeor consent of the user. It is a Windows PE EXE file. The file is 28,796 bytesin size. It is not packed in any...
Trojan-Proxy.Win32.Daemonize.a
This Trojan launches a proxy server on the victim machine without the user'sknowledge or consent. This makes it possible for a remote malicious user toappear as though his actions are being carried...
Trojan-Proxy.Win32.Mitglieder.o
This Trojan launches a proxy mail server on the victim machine. It is a WindowsDLL file. It is 27,136 bytes in size. InstallationThis Trojan will be installed to the victim machine by another...
Trojan-Proxy.Win32.Agent.x
This Trojan launches a proxy server on the victim machine without the knowledgeor consent of the user. It is a Windows PE EXE file. The file is approximately17KB in size. It is packed using...
Trojan-Proxy.Win32.Xorpix.v
This Trojan program makes it possible for a remote malicious user to use thevictim machine as a proxy server. It is a Windows PE EXE file. The file isapproximately 15KB in size. It is written in...
Trojan-Proxy.Win32.Xorpix.ar
This Trojan program makes it possible for a remote malicious user to use thevictim machine as a proxy server. It is a Windows PE EXE file. The file isapproximately 17KB in size. It is packed...
|