CCProxy

Unwanted - App

Here are several analysis report of CCProxy. This program seems to have different installers which create different folders.

Found files - view
C:\CCProxy\CCProxy.dll
C:\CCProxy\CCProxy.exe
C:\CCProxy\CCProxy.ini
C:\CCProxy\web\proxyadmin.php
C:\CCProxy\zlib1.dll
%CommonPrograms%\CCProxy\CCProxy.lnk
%CommonPrograms%\CCProxy\Uninstall CCProxy.lnk
 

Found files 
%Temp%\CCProxy.exe
%Temp%\CCProxy.dll
%Temp%\CCProxy.ini
  view

Found files 
C:\Program Files\C\Program Files\laass.exe
C:\Windows\System32\CCProxy.ini
  view

Found files 
C:\Windows\java\svchost.exe
C:\Windows\java\sc.exe    
C:\Windows\java\CCProxy.ini
  view

Found files
C:\Windows\System32\c\syswin\CCProxy.exe  view

Found files
%AppData%\Thinstall\CCProxy 7.1\%drive_C%\CCProxy\CCProxy.ini   view

Found files
C:\Windows\System32\dllcache\svchost.exe   view

Found files
C:\WINNT\system32\winlogo.exe   view

Found files
C:\Windows\System32\ccBuilder.exe    view

Found files
C:\Windows\addins\CCProxy.dll  view

Found files 
C:\Windows\System32\dllcache\basic.exe
C:\Windows\System32\dllcache\delphi.exe
C:\Windows\System32\IExp1orer.exe
C:\Windows\System32\spool\NTSVC.exe
C:\Windows\System32\spool\CCProxy.ini
 view

(Full path for the short folder names can be found on this link

 

The removal process may require using the System Restore, enabling to view hidden files and folders, removing entries from the Windows Startup, booting in the Safe Mode, using the System File Checker application etc. These steps vary slightly in different versions of Microsoft Windows.

Some steps are essential

To remove virus processes from the Task Manager
To search and delete virus files from the hard disk. Enable to view "hidden files and folders" before you search.  Otherwise virus files inside the hidden folders will not be found.
To remove obsolete registry keys using CCleaner

Detailed instructions and a number of free Tools are listed on this link

Different ways to prevent malicious files from entering the computer on this link.

 

Reprinted with permission from Threatexpert.com

Please see the Disclaimer  


FAQ

Subscribe to me on YouTube