ItsGeorge
Topic Starter
Hello,
Noticed the Great deal of knowledge here!! Hopefully someone can help, I know just enough to destroy my system
Recently my computers router (A linksys) went inop. My systems 1 XP, and 1 Win2K both showed connectivity,
I called ISP they said everything was fine, etc, etc… But couldn't access the internet?? Until I went direct to modem then it worked!? had Access great, I started looking at(Googling) dhcp postings in forums when I came across "Possible Virus"
It never dawned on me…NEVER opening questionable emails, or visiting dark sites, Having my Win 2K, Ad-Aware & Avast always up to date, and running online scanners 2x month plus windows mal-ware cleaner, and my router for firewall(So I thought) In Short, It wasn't enough! I got a darn bug!!
Brief run-down of what steps I've taken until I can follow your FULL instructions.
1) First installed "Zone alarm" so I could stop this thing and rid my system.
2) Ran Kaspersky, Trend-Micro, Panda (All Online) nothing was found initially.
EDIT: ooops Also, Spybot S&D
3) Ran Stinger
4) Ran ewido.
Ewido found:
Name: Proxy.Ranky
Path: C:\WINNT\system32\tsmart.exe
Risk: High
Note*
Didn't notice anything off in taskmanager(Always watch how many are running, had 23 up until Sat. 10th) until Tcpsvcs.exe, and Tsmart exe.
I was going to start deleting these from my registry…INSTEAD–Currently downloading ewido to run in "Safe mode" and going to download Hijackthis in its own folder.
Then I'll post the information you need. CORRECT?
Thanks,
George
Have/had these 3 questionable Items(I believe one of the scans tried to rid them but "Froze":
worm_sdbot.JC
troj_ranky.HT
jotti found info on tsmart.exe
Service load:
0% 100%
File: tsmart.exe
Status:
INFECTED/MALWARE
MD5 d14677965cdab7828669a7679e1b243b
Packers detected:
PE_PATCH, UPACK
Scanner results
AntiVir
Found Trojan/Proxy.Ranky.EX.2
ArcaVir
Found Trojan.Proxy.Ranky.Gen.18104.MX
Avast
Found nothing
AVG Antivirus
Found Proxy.CZL
BitDefender
Found Trojan.Proxy.Ranky.EX
ClamAV
Found nothing
Dr.Web
Found DLOADER.Trojan (probable variant)
F-Prot Antivirus
Found nothing
Fortinet
Found W32/Ranck.HT!tr
Kaspersky Anti-Virus
Found Trojan-Proxy.Win32.Ranky.gen
NOD32
Found a variant of Win32/TrojanProxy.Ranky
Norman Virus Control
Found Sandbox: W32/Malware; [ General information ]
* File length: 18104 bytes.
[ Changes to registry ]
* Creates value "Evawwffe"="c:\sample.exe" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
[ Network services ]
* Downloads file from http://rogerr.homeunix.net/a.php?29075 as c:\vewadw.
[ Security issues ]
* Possible backdoor functionality [UNKNOWN] port 29075.
[ Process/window information ]
* Creates a mutex AllAlone.
* Will automatically restart after boot (I'll be back…).
UNA
Found nothing
VirusBuster
Found nothing
VBA32
Found Trojan-Proxy.Win32.Ranky.gen
Noticed the Great deal of knowledge here!! Hopefully someone can help, I know just enough to destroy my system
Recently my computers router (A linksys) went inop. My systems 1 XP, and 1 Win2K both showed connectivity,
I called ISP they said everything was fine, etc, etc… But couldn't access the internet?? Until I went direct to modem then it worked!? had Access great, I started looking at(Googling) dhcp postings in forums when I came across "Possible Virus"
It never dawned on me…NEVER opening questionable emails, or visiting dark sites, Having my Win 2K, Ad-Aware & Avast always up to date, and running online scanners 2x month plus windows mal-ware cleaner, and my router for firewall(So I thought) In Short, It wasn't enough! I got a darn bug!!
Brief run-down of what steps I've taken until I can follow your FULL instructions.
1) First installed "Zone alarm" so I could stop this thing and rid my system.
2) Ran Kaspersky, Trend-Micro, Panda (All Online) nothing was found initially.
EDIT: ooops Also, Spybot S&D
3) Ran Stinger
4) Ran ewido.
Ewido found:
Name: Proxy.Ranky
Path: C:\WINNT\system32\tsmart.exe
Risk: High
Note*
Didn't notice anything off in taskmanager(Always watch how many are running, had 23 up until Sat. 10th) until Tcpsvcs.exe, and Tsmart exe.
I was going to start deleting these from my registry…INSTEAD–Currently downloading ewido to run in "Safe mode" and going to download Hijackthis in its own folder.
Then I'll post the information you need. CORRECT?
Thanks,
George
Have/had these 3 questionable Items(I believe one of the scans tried to rid them but "Froze":
worm_sdbot.JC
troj_ranky.HT
jotti found info on tsmart.exe
Service load:
0% 100%
File: tsmart.exe
Status:
INFECTED/MALWARE
MD5 d14677965cdab7828669a7679e1b243b
Packers detected:
PE_PATCH, UPACK
Scanner results
AntiVir
Found Trojan/Proxy.Ranky.EX.2
ArcaVir
Found Trojan.Proxy.Ranky.Gen.18104.MX
Avast
Found nothing
AVG Antivirus
Found Proxy.CZL
BitDefender
Found Trojan.Proxy.Ranky.EX
ClamAV
Found nothing
Dr.Web
Found DLOADER.Trojan (probable variant)
F-Prot Antivirus
Found nothing
Fortinet
Found W32/Ranck.HT!tr
Kaspersky Anti-Virus
Found Trojan-Proxy.Win32.Ranky.gen
NOD32
Found a variant of Win32/TrojanProxy.Ranky
Norman Virus Control
Found Sandbox: W32/Malware; [ General information ]
* File length: 18104 bytes.
[ Changes to registry ]
* Creates value "Evawwffe"="c:\sample.exe" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
[ Network services ]
* Downloads file from http://rogerr.homeunix.net/a.php?29075 as c:\vewadw.
[ Security issues ]
* Possible backdoor functionality [UNKNOWN] port 29075.
[ Process/window information ]
* Creates a mutex AllAlone.
* Will automatically restart after boot (I'll be back…).
UNA
Found nothing
VirusBuster
Found nothing
VBA32
Found Trojan-Proxy.Win32.Ranky.gen