Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2005 (3.99) |
| Protection available since | 23 September 2005 12:52:10 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/SocksPr-D is a proxy server Trojan.
The proxy server runs continuously in the background listening on a randomly chosen TCP port and allows data to be routed through the computer.
The proxy may be used to forward spam.
Troj/SocksPr-D includes functionality to send notification messages to remote locations.
The following registry entry is created to run Troj/SocksPr-D on startup:
HKLM\sOFTWARE\Microsoft\Windows\CurrentVersion\Run\
WheelsMouse
<path to Trojan>
If run with sufficient rights Troj/SocksPr-D will install itself as an application authorized by the Window Firewall to communicate with the outside world.
The following registry entry is also created:
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\
DataBasePathLen
<server port number>
