Content

AnalogX-Proxy

Type
Program
SubType
Tool
Discovery Date
03/10/2003
Minimum DAT
4253 (03/19/2003)
Updated DAT
4655 (12/21/2005)
Minimum Engine
5.1.00
Description Added
04/29/2003
Description Modified
04/29/2003 10:53 AM (PT)

Tab Navigation

Characteristics

This is an application, not a virus or trojan. It is a proxy server application which enables users to route various protocol requests through a single machine (running the proxy server).

When run, the application will display a message box alerting the user to the danger of running the proxy in an open state:

Once the application is running, an icon is visible in the systray, enabling the application to be configured:

The application has been bundled into various IRC/Flood malware packages, coupled with a trojan file designed to launch the application. The above warning message is quickly removed when the application is launched via the trojan launcher file. The launcher (which is nothing to do with the perfectly legitimate application) is detected as malware, as AnalogX-Proxy.ldr.

Removal

Potentially Unwanted Applications can be detected with VirusScan 7 and/or the command line scanner with the /PROGRAM switches.

  1. Click the START button
  2. Click RUN
  3. Type COMMAND and hit ENTER
  4. Type:

    c:\progra~1\common~1\networ~1\viruss~1\4.0.xx\scan.exe c: /program /sub

    and hit ENTER.

Users running VirusScan 7 or later can also enable application or joke detection via the configuration option "Find potentially unwanted programs" (Advanced section - see example below), within the VirusScan GUI as shown below:

Corporate Users:

This applies for the On-Access scanner too.

Retail Users:

Contact the program author (origin) for removal instructions.

Aliases

Aliases

    N/A