Sophos

Troj/Proxy-U

Aliases
  • Trojan-Dropper.Win32.Agent.ta
  • TROJ_AGENT.BCB
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 19 October 2005 07:48:12 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Proxy-U is a proxy Trojan for the Windows platform.

The Trojan attempts to havest email addresses from the infected computer and
transmit them to a third party, as well as download and execute other
components from the web.

When Troj/Proxy-U is installed the following files are created:

<System>\birdihuy.dll
<System>\birdihuy32.dll

The following registry entry is set:

HKCU\Software\Classes\CLSID\(F33812FB-F35C-4674-90F6-FD757C419C51)
InProcServer32
(default)
<System>\birdihuy32.dll

Registry entries are created under:

HKCU\Software\Classes\CLSID\(F33812FB-F35C-4674-90F6-FD757C419C51)
InProcServer32\

To avoid detection, Troj/Proxy-U may attempt to terminate various Anti-Virus
and security related applications.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer