Sophos

Troj/Proxy-H

Aliases
  • Trojan-Proxy.Win32.Small.av
  • W32/Goldun.D@pws
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 2 February 2005 21:34:09 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Proxy-H is a proxy Trojan.

Troj/Proxy-H allows a remote user to route traffic through the infected system.

When first run, the Trojan copies itself to the Windows system folder as AIG.EXE and creates the following registry entry in order to run itself on system startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
aIg
<Windows system folder>\aIg.exe /a

Troj/Proxy-H may be dropped together with a Trojan of the Goldun family.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer