Sophos

Troj/Proxyser-R

Aliases
  • Trojan-Spy.Win32.Sters.f
  • BackDoor-CWW
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from March 2006 (4.03)
Protection available since 24 January 2006 05:25:25 (GMT)
Last updated 24 January 2006 15:25:14 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Proxyser-R is a proxy Trojan for the Windows platform.

Once installed, Troj/Proxyser-R sets up a SOCKS proxy server.

Troj/Proxyser-R includes functionality to access the internet and communicate with a remote server via HTTP.

The following registry entry is created to run Troj/Proxyser-R on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Windows Logon Process
<Windows>\winlogon.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Windows Session Manager Subsystem
<Windows>\smss.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update
AUOptions
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update
ResetAU
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update
DetectionStartTime

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update
ScheduledInstallDay
0

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update
ScheduledInstallTime
3

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
DisableNotifications
1

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
DoNotAllowExceptions
0

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
EnableFirewall
0

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer