Analysis by: Anthony Joe Melgarejo

 PLATFORM:

Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Hacking Tool

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This hacking tool may be manually installed by a user.

It connects to certain websites to send and receive information.

  TECHNICAL DETAILS

File Size: 2,528,340 bytes
File Type: EXE
Memory Resident: No
Initial Samples Received Date: 03 Jul 2013
Payload: Connects to URLs/IPs

Arrival Details

This hacking tool may be manually installed by a user.

Installation

This hacking tool adds the following folders:

  • %All Users Profile%\Start Menu\Programs\ProxyShell Hide IP
  • %Program Files%\ProxyShell
  • %Program Files%\ProxyShell\ProxyShell Hide IP

(Note: %All Users Profile% is the All Users folder, where it usually is C:\Documents and Settings\All Users on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\ProgramData on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.. %Program Files% is the Program Files folder, where it usually is C:\Program Files on all Windows operating system versions; C:\Program Files (x86) for 32-bit applications running on Windows 64-bit operating systems.)

It drops the following files:

  • %All Users Profile%\Start Menu\Programs\ProxyShell Hide IP\ProxyShell Hide IP on the Web.url
  • %All Users Profile%\Start Menu\Programs\ProxyShell Hide IP\ProxyShell Hide IP.lnk
  • %All Users Profile%\Start Menu\Programs\ProxyShell Hide IP\Uninstall ProxyShell Hide IP.lnk
  • %Program Files%\ProxyShell\ProxyShell Hide IP\ACE.dll
  • %Program Files%\ProxyShell\ProxyShell Hide IP\BrowsersResetting.exe
  • %Program Files%\ProxyShell\ProxyShell Hide IP\curl.exe
  • %Program Files%\ProxyShell\ProxyShell Hide IP\dbghelp.dll
  • %Program Files%\ProxyShell\ProxyShell Hide IP\ErrorReport.exe
  • %Program Files%\ProxyShell\ProxyShell Hide IP\license.txt
  • %Program Files%\ProxyShell\ProxyShell Hide IP\msvcp100.dll
  • %Program Files%\ProxyShell\ProxyShell Hide IP\msvcr100.dll
  • %Program Files%\ProxyShell\ProxyShell Hide IP\proxyshell.exe
  • %Program Files%\ProxyShell\ProxyShell Hide IP\unins000.dat
  • %Program Files%\ProxyShell\ProxyShell Hide IP\unins000.exe

(Note: %All Users Profile% is the All Users folder, where it usually is C:\Documents and Settings\All Users on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\ProgramData on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.. %Program Files% is the Program Files folder, where it usually is C:\Program Files on all Windows operating system versions; C:\Program Files (x86) for 32-bit applications running on Windows 64-bit operating systems.)

Other System Modifications

This hacking tool adds the following registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
ProxyShell Hide IP_is1

HKEY_CURRENT_USER\Software\ProxyShell

HKEY_CURRENT_USER\Software\ProxyShell\
HideIPStd

It adds the following registry entries:

HKEY_CURRENT_USER\Software\ProxyShell\
HideIPStd
Crash = "1"

HKEY_CURRENT_USER\Software\ProxyShell\
HideIPStd
ConnectServer = "0"

HKEY_CURRENT_USER\Software\ProxyShell\
HideIPStd
UID = "C8CA3E10EF8611E28002"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
AutoConfigURL = "http://127.0.0.1:9000/proxy.pac"

Other Details

This hacking tool adds the following registry entries to add an uninstall option to the Control Panel:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
ProxyShell Hide IP_is1
UninstallString = "%Program Files%\ProxyShell\ProxyShell Hide IP\unins000.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
ProxyShell Hide IP_is1
QuietUninstallString = ""%Program Files%\ProxyShell\ProxyShell Hide IP\unins000.exe" /SILENT"

It connects to the following website to send and receive information:

  • http://www.{BLOCKED}hell.com/update/pshin1000.html?version={version number}&crash=0
  • http://{BLOCKED}shell.com/purchase.html?p=pshin

NOTES:
This is Trend Micro's detection for risky proxy tools that are used to bypass firewalls and administrator's network rules or policy.

  SOLUTION

Minimum Scan Engine: 9.300
SSAPI PATTERN File: 1.418.35
SSAPI PATTERN Date: 16 Jul 2013

Step 1

Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.

Step 2

Identifying the Grayware Files

Download the latest spyware pattern file and scan your computer. Note the path and file name of all files detected as HKTL_HIDEIP.

Step 3

Remove HKTL_HIDEIP by using its own Uninstall option

[ Learn More ]
To uninstall the grayware process

Step 4

Delete this registry key

[ Learn More ]

Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.

  • In HKEY_CURRENT_USER\Software
    • ProxyShell

Step 5

Delete this registry value

[ Learn More ]

Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.

  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
    • %Program Files%\ProxyShell\ProxyShell Hide IP\proxyshell.exe = "%Program Files%\ProxyShell\ProxyShell Hide IP\proxyshell.exe:*:Enabled:ProxyShell Hide IP"

Step 6

Search and delete this folder

[ Learn More ]
Please make sure you check the Search Hidden Files and Folders checkbox in the More advanced options option to include all hidden folders in the search result.
  • %All Users Profile%\Start Menu\Programs\ProxyShell Hide IP
  • %Program Files%\ProxyShell

Step 7

Scan your computer with your Trend Micro product to delete files detected as HKTL_HIDEIP. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.


Did this description help? Tell us how we did.