Trojan . Z-proxy (Summary)
Software Name: Z-proxy
Company Name:
Product Name: Z-proxy
Classification: Trojan
Website: http://z-proxy.com; http://x-moovie.com
Brief:
Silently downloads files related to an adult dialer from z-proxy.com and x-moovie.com, which is an adult site. Can allow remote access to a users computer and sends users unique system information to its controlling servers.
IMPORTANT!
Some of the Trojan.Z-proxy components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of Z-proxy
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
Z-proxy might create following folders (and inject its files inside
the folders):
n/a
Z-proxy might create following files (some of the files might be
loaded in memory while the software is running):
- %SYSTEMDRIVE%.exe
- %SYSTEMDRIVE%.exe
- %SYSTEMDRIVE%\temp.tgs
- %DESKTOP%\on-line show.lnk
- %WINDOWS%\MSXMIDI.EXE
- %SYSTEM%\adkfe.tof
- %SYSTEM%\sefpnt.dll
- %SYSTEM%\sgchost.exe
- %SYSTEM%\suchostp.exe
- %SYSTEM%\suchosts.exe
- %SYSTEM%\xopert.dll
- %SYSTEM%\zstup.dll
Z-proxy is often accompanied by the following tracking cookies:
Z-proxy might create following registry keys (and inject subkeys
and values):
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RAS AutoDial\Control
Z-proxy might create following registry values:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|GLSetIT32
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|GLSetIT32
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Configuration Service
Z-proxy might create registry values with following data:
n/a
Z-proxy might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for Z-proxy free of charge
|