Friday, January 23, 2009

Tiny Proxy.exe : One Evil Mofo!

Symptoms:

Youtube and/or other SQL based streams dont work or stall halfway.

Any searches using Google /Google toolbar (when the link is clicked) get redirected to various nonsensical sites and the search turns into a wild goose chase.

My friend, your computer has been affected by Tiny Proxy.exe.... the mother of all malwares!

According to Banu.com, "Tinyproxy is a light-weight HTTP proxy daemon for POSIX operating systems, released under the GNU GPL license. Designed from the ground up to be fast and yet small, it is an ideal solution for use cases such as embedded deployments where a full featured HTTP proxy is required, but the system resources for a larger proxy are unavailable."


Here's what Tiny Proxy affects:

File name / Threat name / Threats count
C:\Program Files\tinyproxy\tinyproxy.exe//PE_Patch.PECompact//PecBundle//PECompact/C:\Program Files\tinyproxy\tinyproxy.exe//PE_Patch.PECompact//PecBundle//PECompact
Infected: Trojan.Win32.Agent.atpj 1

C:\Program Files\tinyproxy\tinyproxy.exe Infected: Trojan.Win32.Agent.atpj 1
C:\WINDOWS\SYSTEM32\900053\900053.dll Infected: not-a-virus:AdWare.Win32.E404.jf 1

This malware is so nasty, it has been also known to affect Ubuntu & OSX!

Solution:
I've had this issue and last night, my friend Arun suggested a program called AVG to remove this small but troublesome worm.

It worked! Download AVG for free from here:

Labels: , , , , , ,