CCProxy
Last Updated on Wednesday, 27 June 2012 17:10 Thursday, 16 December 2010 08:58
Here are several analysis report of CCProxy. This program seems to have different installers which create different folders.
Found files - view
C:\CCProxy\CCProxy.dll
C:\CCProxy\CCProxy.exe
C:\CCProxy\CCProxy.ini
C:\CCProxy\web\proxyadmin.php
C:\CCProxy\zlib1.dll
%CommonPrograms%\CCProxy\CCProxy.lnk
%CommonPrograms%\CCProxy\Uninstall CCProxy.lnk
Found files
%Temp%\CCProxy.exe
%Temp%\CCProxy.dll
%Temp%\CCProxy.ini
view
Found files
C:\Program Files\C\Program Files\laass.exe
C:\Windows\System32\CCProxy.ini
view
Found files
C:\Windows\java\svchost.exe
C:\Windows\java\sc.exe
C:\Windows\java\CCProxy.ini
view
Found files
C:\Windows\System32\c\syswin\CCProxy.exe view
Found files
%AppData%\Thinstall\CCProxy 7.1\%drive_C%\CCProxy\CCProxy.ini view
Found files
C:\Windows\System32\dllcache\svchost.exe view
Found files
C:\WINNT\system32\winlogo.exe view
Found files
C:\Windows\System32\ccBuilder.exe view
Found files
C:\Windows\addins\CCProxy.dll view
Found files
C:\Windows\System32\dllcache\basic.exe
C:\Windows\System32\dllcache\delphi.exe
C:\Windows\System32\IExp1orer.exe
C:\Windows\System32\spool\NTSVC.exe
C:\Windows\System32\spool\CCProxy.ini
view
(Full path for the short folder names can be found on this link)
The removal process may require using the System Restore, enabling to view hidden files and folders, removing entries from the Windows Startup, booting in the Safe Mode, using the System File Checker application etc. These steps vary slightly in different versions of Microsoft Windows.
Some steps are essential
To remove virus processes from the Task Manager
To search and delete virus files from the hard disk. Enable to view "hidden files and folders" before you search. Otherwise virus files inside the hidden folders will not be found.
To remove obsolete registry keys using CCleaner
Detailed instructions and a number of free Tools are listed on this link.
Different ways to prevent malicious files from entering the computer on this link.
Reprinted with permission from Threatexpert.com
Please see the Disclaimer
| < Prev | Next > |
|---|

