Description
This description is for a backdoor trojan, which when executed provides an attacker with unauthorized remote access to the compromised machine.
The characteristics of this Trojan with regards to the file names, port number used, etc will differ, depending on the way in which the attacker had configured it. Hence, this is a general description.
Indication of Infection
Presence of files and registry entries mentioned earlier
Methods of Infection
Trojans do not self-replicate. They spread manually, often under the premise that the executable is something beneficial. Trojans may also be received as a result of poor security practices, or un-patched machines and vulnerable systems.
Distribution channels include IRC, peer-to-peer networks, email, newsgroups postings, etc.
Aliases
Mal/Emogen-Y [Sophos], Trojan.Whitewell [Symantec], Trojan.Win32.Scar.agqx [Kaspersky]