How to remove Trojan Proxy

Hi :slight_smile:

My friend believes that his computer is infected with Win32/TrojanProxy.Agent.NVF

http://todxhost.vndv.com/uploads/9897_dafsdgsdfhsdf.PNG

Looks like my friend installed this file hxxp://wxxw.vsetutvse.net/11.exe(Avast blocks this website but can,t detect virus in this file )

Virustotal: http://www.virustotal.com/analisis/c054e607a3b132c3d386a581b1aaaf383f894a55d82f3de185e34d4aeb8febd2-1265668658
Camas.Comodo: http://camas.comodo.com/cgi-bin/submit?file=c054e607a3b132c3d386a581b1aaaf383f894a55d82f3de185e34d4aeb8febd2

Should I send this file for analysis?

Thank you and have a nice day. :slight_smile:

well virustotal is showing that NOD32 is detecting it, so your friend could try ESET online scanner to remove it

http://www.eset.com/onlinescan/

yep, send that in for analysis. It doesn’t look anywhere near legit; here’s what I found.

  • Creates a file called zzop93.dll in %WINDIR%\system32
  • Punches a hole in the Windows firewall by creating a Registry key: HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List"D:\DOCS\11.exe" (no quotes)=“D:\DOCS\11.exe:*:Enabled:11” (no quotes, and no equals sign; that’s just the value of the key)

I also noticed 11.exe doing a lot of Process Profiling, according to Process Monitor; this kind of event involves measuring CPU & RAM load.
Finally, it looks like 11.exe is doing a lot of meddling in services, including password services; that could be the OS (Sandboxie didn’t say; it just listed several Registry keys involved with services), but I doubt it.

Hi computerfreaker, Pondus and JuninhoSlo,

Here is the 11.exe information, cloaked malware/downloader comes in various flaws:
http://www.threatexpert.com/files/11.exe.html
http://www.prevx.com/filenames/94073847532732801-X1/11.EXE.html
http://www.prevx.com/filenames/2824219161907404452-842665062/11.EXE.html (derived info)

But it also can be a false flag for a driver file, so victim should upload to virustotal.com
requester.11.exe again is dangerous malware…

polonus

Here is the 11.exe information, cloaked malware/downloader comes in various flaws:
http://www.threatexpert.com/files/11.exe.html
http://www.prevx.com/filenames/94073847532732801-X1/11.EXE.html
http://www.prevx.com/filenames/2824219161907404452-842665062/11.EXE.html (derived info)

But it also can be a false flag for a driver file, so victim should upload to virustotal.com
requester.11.exe again is dangerous malware…

polonus

I have the same thing happening to me except that Avast has continued to block the attempts to download hxxp://wxxw.vsetutvse.net/11.exe - so I am not infected with 11.exe but with something else that tries to run/download 11.exe from vsetutvse.net. There is an attempt to connect every 5 or 10 minutes and it’s been going on for several days.

These attempts aren’t being made from a website but there is something on my machine that is trying periodically. I have been unable to find the source on my machine. I’ve run Malwarebytes, SuperAntiSpyware, ESET, SpywareDoctor, SpyBot, UnHackMe and Avast but none of them find the file on my machine that is trying to link to vsetutvse.net. Everything I see in HiJackThis looks legit.

Any suggestions on how to find the rogue file?

Hi Mark,

Maybe this information will help you

http://home.mcafee.com/VirusInfo/VirusProfile.aspx?key=233628#none

http://forum.bitdefender.com/index.php?showtopic=3575

Have you try with ComboFix scanner for your system?

Any suggestions on how to find the rogue file?
Try this

Dr.Web CureIt!® http://www.freedrweb.com/cureit/?lng=en
How Do I Use Dr.Web CureIt!? http://www.freedrweb.com/cureit/how_it_works/

Norman Malware Cleaner http://www.norman.com/support/support_tools/58732/en

Thanks for the suggestions. Unfortunately, the problem remained.

In the end, I accepted defeat and restored from a backup - sadly it’s 3-months old :-X . So I now have to bring it up to date but at least I no longer have the original problem. Thanks again.