Trojan-Proxy.Win32.Cidra.a
| Alert Level : | Medium |
| Discovered: | Feb 19 2007 |
| Tag: | Trojan-Proxy-Servers |
| Discoverer and Source: | http://www.kaspersky.com/ |
Malware Behavior and Technical Description
This Trojan program turns the victim machine into a proxy server. It is a Windows PE EXE file. It is 57,344 bytes in size. Payload
The Trojan creates a SOCKS proxy server on a randomly chosen TCP port. The number of the open port and the victim machine
Removal Trojan-Proxy.Win32.Cidra.a instructions:
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
- Use Task Manager to terminate the Trojan process.
- Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
- Delete the following key from the system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UsbD" = "usb_d.exe" - Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).
Need help? Live computer support via remote at SupportSpace |

