Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

TROJ_PROXY.LI

BugsAlert Home > TROJ_PROXY.LI
 
 

This Trojan may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.

Upon execution, this Trojan drops a copy of itself in the Windows system folder. It then registers itself as a system service to ensure its automatic execution at every system startup.

This Trojan opens random ports and acts as a proxy server which is an intermediary between a user and a server. A proxy usually listens to a port, and when it receives an incoming request, it forwards the said request to the target server. When the proxy receives a reply, it forwards the reply to the original user.

As a proxy server, this Trojan allows a remote malicious user to use the affected system in concealing the said author's identity when performing malicious activities.




Original Source: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_PROXY.LI

Learn more about TROJ_PROXY.LI
 
Tags: troj proxy.li

Related Items

      Vuln: Academic Web Tools CMS 1.4.2.8 Multiple Input Validation Vulnerabilities

      Microsoft Security Advisory (906574): Clarification of Simple File Sharing and ForceGuest - 8/23/2005

      TROJ_VUNDO.AGY

      CVE-2008-2754 (efiction)

      Gentoo: PHP Toolkit Data disclosure and Denial of Service

      Bugtraq: [SECURITY] [DSA 1569-1] New cacti packages fix multiple vulnerabilities

      Airspan WiMAX ProST Web Interface Authentication Bypass

 

Pixel