Largest Directoty of Internet Security Software

Internet Security Threats

Home Software Threats Security
News
 

Trojan-Proxy.Win32.Agent.x

RISK LEVEL:2



This Trojan launches a proxy server on the victim machine without the knowledgeor consent of the user. It is a Windows PE EXE file. The file is approximately17KB in size. It is packed using PECompact. The unpacked file is approximately30KB in size.

Installation

When launched, the Trojan creates the following folder:

%Documents and Settings%\Application Data\Microsoft\sr64

It then copies its executable file to this folder under a random name whichis made up of capital letters and an .exe extension.

The Trojan also adds a link to its executable file in the system registry,ensuring that the Trojan will be launched when Windows is rebooted on the victimmachine:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"sr64" = "<path and name of Trojan executable file>"

The Trojan also extracts the following file from its body:

  • %Documents and Settings%\Application Data\Microsoft\sr64\sr32.dll— this file is 7,168 bytes in size.

The Trojan launches an HTTP proxy server on TCP port 3380 and a SOCKS proxyservier on TCP port 3382.

It then sends the version of the operating system, the IP address of the victimmachine, and the numbers of open ports to the remote malicious user's site.

The DLL file dropped by the Trojan masks the presence of files on the harddisk and registry keys which contain the substring "sr64" in their names.

If your computer does not have an up-to-date antivirus, or does not have anantivirus solution at all, follow the instructions below to delete the maliciousprogram:

  1. Use Task Manager to terminate the Trojan process.
  2. Delete the following folder and its contents
    Documents and Settings%\Application Data\Microsoft\sr64
  3. Delete the following system registry key parameter:
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "sr64" = "<path and name of Trojan executable file>"
  4. Update your antivirus databases and perform a full scan of thecomputer (download a trial version of Kaspersky Anti-Virus).


Printed From:http://www.viruslist.com/en/viruses/encyclopedia?virusid=41042


Similar Virus/Threat >>
  •   Trojan-Proxy.Win32.Agent.o
  • This Trojan launches a proxy server on the victim machine without the knowledgeor consent of the user. It is a Windows PE EXE file. It is 139,264 bytes insize. It is not packed in any way. It is...
  •   Trojan-Proxy.Win32.Agent.q
  • This Trojan launches a proxy server on the victim machine without the knowledgeor consent of the user. It is a Windows PE EXE file. The file is 28,796 bytesin size. It is not packed in any...
  •   Trojan-Proxy.Win32.Agent.v
  • This Trojan launches a proxy server on the victim machine without the knowledgeor consent of the user. It is a Windows PE EXE file. The file is approximately19KB in size. It is packed using...
  •   Trojan-Proxy.Win32.Daemonize.a
  • This Trojan launches a proxy server on the victim machine without the user'sknowledge or consent. This makes it possible for a remote malicious user toappear as though his actions are being carried...
  •   Trojan-Proxy.Win32.Mitglieder.o
  • This Trojan launches a proxy mail server on the victim machine. It is a WindowsDLL file. It is 27,136 bytes in size. InstallationThis Trojan will be installed to the victim machine by another...
  •   Trojan-Proxy.Win32.Xorpix.v
  • This Trojan program makes it possible for a remote malicious user to use thevictim machine as a proxy server. It is a Windows PE EXE file. The file isapproximately 15KB in size. It is written in...
  •   Trojan-Proxy.Win32.Xorpix.ar
  • This Trojan program makes it possible for a remote malicious user to use thevictim machine as a proxy server. It is a Windows PE EXE file. The file isapproximately 17KB in size. It is packed...


  • Window Washer
  • symantec PCanywhere 12.0
  • Kaspersky Anti-Hacker
  • iSpyNOW
  • Diet Kaza

  • Acronis Privacy Expert Suite 8.0
    (31,781KB - $29.99)
    AIM Spy Monitor 2007
    (3,145KB - $39.99)
    BlazingTools Secure Office
    (1,301KB - $54.95)
    Yahoo! Messenger Spy Monitor 2007
    (4,034KB - $39.99)
    Encrypt my Folder
    (1,530KB - $24.95)

    Cookie Cleaner   |    History Eraser   |    Popup Killer   |   Firewall   |   Antivirus   |   Security Encryption   |   UnInstaller   |   Security News
    eTrust Pestpatrol Anti-Spyware   PestPatrol 5   Ad-Aware SE Removal   Ad-Aware SE   Ad-Watch   SpyFighter Cleaner Pro   Free Adware Remover   Spy Sweeper  Webroot Spy Sweeper 
    Copyright © 2002-2007 Internet Security Software.All rights reserved.
    Directory of Internet Security Software - Cookie & Cache Cleaner, History & Evidence Eraser, Popup Killer, Firewall