This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware Trojan discovered, brief synopsis.

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Noticed the Great deal of knowledge here!! Hopefully someone can help, I know just enough to destroy my system :)

Recently my computers router (A linksys) went inop. My systems 1 XP, and 1 Win2K both showed connectivity,
I called ISP they said everything was fine, etc, etc… But couldn't access the internet?? Until I went direct to modem then it worked!? had Access great, I started looking at(Googling) dhcp postings in forums when I came across "Possible Virus"
It never dawned on me…NEVER opening questionable emails, or visiting dark sites, Having my Win 2K, Ad-Aware & Avast always up to date, and running online scanners 2x month plus windows mal-ware cleaner, and my router for firewall(So I thought) In Short, It wasn't enough! I got a darn bug!! :(

Brief run-down of what steps I've taken until I can follow your FULL instructions.

1) First installed "Zone alarm" so I could stop this thing and rid my system.

2) Ran Kaspersky, Trend-Micro, Panda (All Online) nothing was found initially.
EDIT: ooops Also, Spybot S&D
3) Ran Stinger
4) Ran ewido.
Ewido found:
Name: Proxy.Ranky
Path: C:\WINNT\system32\tsmart.exe
Risk: High

Note*
Didn't notice anything off in taskmanager(Always watch how many are running, had 23 up until Sat. 10th) until Tcpsvcs.exe, and Tsmart exe.


I was going to start deleting these from my registry…INSTEAD–Currently downloading ewido to run in "Safe mode" and going to download Hijackthis in its own folder.
Then I'll post the information you need. CORRECT? :blink:

Thanks,
George









Have/had these 3 questionable Items(I believe one of the scans tried to rid them but "Froze":
worm_sdbot.JC
troj_ranky.HT



jotti found info on tsmart.exe

Service load:
0% 100%
File: tsmart.exe
Status:
INFECTED/MALWARE
MD5 d14677965cdab7828669a7679e1b243b
Packers detected:
PE_PATCH, UPACK
Scanner results
AntiVir
Found Trojan/Proxy.Ranky.EX.2
ArcaVir
Found Trojan.Proxy.Ranky.Gen.18104.MX
Avast
Found nothing
AVG Antivirus
Found Proxy.CZL
BitDefender
Found Trojan.Proxy.Ranky.EX
ClamAV
Found nothing
Dr.Web
Found DLOADER.Trojan (probable variant)
F-Prot Antivirus
Found nothing
Fortinet
Found W32/Ranck.HT!tr
Kaspersky Anti-Virus
Found Trojan-Proxy.Win32.Ranky.gen
NOD32
Found a variant of Win32/TrojanProxy.Ranky
Norman Virus Control
Found Sandbox: W32/Malware; [ General information ]

* File length: 18104 bytes.

[ Changes to registry ]
* Creates value "Evawwffe"="c:\sample.exe" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".

[ Network services ]
* Downloads file from http://rogerr.homeunix.net/a.php?29075 as c:\vewadw.

[ Security issues ]
* Possible backdoor functionality [UNKNOWN] port 29075.

[ Process/window information ]
* Creates a mutex AllAlone.
* Will automatically restart after boot (I'll be back…).
UNA
Found nothing
VirusBuster
Found nothing
VBA32
Found Trojan-Proxy.Win32.Ranky.gen
run what you have, ewido and your AV in safe mode. the router: problem came before or after installing ZA? check connections, make sure cable from modem is plugged into the routers WAN port check configuration in router setup.

run what you have, ewido and your AV in safe mode.
the router: problem came before or after installing ZA?
check connections, make sure cable from modem is plugged into the routers WAN port
check configuration in router setup.


Hello, Thanks for the reply.

Ran everything in safe mode posted results in proper HJT area..HERE

This "router problem" occured before ZA was downloaded,
I now believe it was caused by the Trojan somehow.
Sad, I thought the linksys "hard firewall" and XP machines firewall would protect this windows 2000 system..I digress.

Linsys worked fine for 2-3 months, I tried using the internet one A.M to find it inop.
Called the Host and since all conectivity seemed OK, they suggested taking the Linksys out of the loop and trying direct connect with modem…It worked.
Then the "auto-mailing" started, which avast alerted of, which led to discovering Trojan, which has led to me being here with those who know.

Hope that helps.


EDIT: Odd?? But want to include as much pertinent information in case anyone has this problem and "Googles" it recover. Thanks again

Ran a whois on the ZA alerted & blocked Sbc IP addy trying to access my internet.
[removed]
Record Type: IP Address

SBC Internet Services SBCIS-SIS80-1005 (NET-64-148-0-0-1)
[removed] - [removed]
PAYDAY TODAY LLC-051229065312 SBC06414923814429051229065339 (NET-64-149-238-144-1)
[removed] - [removed]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI