Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of ewido Support Forums > ewido anti-spyware forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 17th, 2006, 06:31 PM
cliffw cliffw is offline
Infrequent Poster
 
Join Date: Apr 2006
Posts: 2
Default trojan keeps returning

My PC caught an unknown trojan that attempts to contact an outside IP.

Scans with Ewido detect it as "proxy.Horst.ai" trojan

What happens is the trojan activates as soon as I connect to the internet, then it writes 3 .exe files to C\documents and settings\windows xp user \ local settings \ temp

the file names are 13exmdulbk.exe , 56exssd32a.exe and install.exe (the first 2 numbers change each time )

Ewido finds the XXexmdulbk.exe file and quarantines it, but it always returns after relogging in to the internet

deleting all 3 files does nothing either, they return also

Looking at the install.exe with notepad, this text string is apparent

Quote:
KERNEL32.DLL PSAPI.DLL WS2_32.DLL WININET.DLL ADVAPI32.DLL LoadLibraryA GetProcAddress VirtualProtect VirtualAlloc VirtualFree ExitProcess GetModuleInformation InternetOpenA

Goggle searches on exmdulbke, proxy.horst.ai and exssd32a have been fruitless

I am hoping to find a way to truly remove this from my system
  #2  
Old April 17th, 2006, 07:42 PM
Eldar's Avatar
Eldar Eldar is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: Vilvoorde (Belgium)
Posts: 2,126
Default Re: trojan keeps returning

Hi cliffw & welcome to Wilders,
Quote:
Originally Posted by cliffw
My PC caught an unknown trojan that attempts to contact an outside IP.

I am hoping to find a way to truly remove this from my system
Best to do a full scan in Safe Mode (no internet), so Ewido can remove all of it.

See if that helps.
__________________
Brabantse leeuw | Eendracht maakt macht
Vista HP SP1 | KIS 2009 | Malware Defender | SUPERAntiSpyware
Opera & Firefox | Barca Pro | Sandboxie | FirstDefense-ISR | ShadowProtect
Rogue/Suspect Anti-Spyware Products & Web Sites
  #3  
Old April 17th, 2006, 08:04 PM
cliffw cliffw is offline
Infrequent Poster
 
Join Date: Apr 2006
Posts: 2
Default Re: trojan keeps returning

Thanks eldar

Since the post ... what I did find was a registry entry in HKEY_CURRENT_USER\RUN called .nvsvc was opening another file called smss.exe in the windows/system directory.

apparently there is also a legitimate windows smss.exe , but this one was part of the trojan

god willin' and the creek don't rise ... this one is gone

I was a bit surprised this one did not have more presence on the internet

One of the side effects was a several second lag when changing websites, that seems to be gone too
  #4  
Old April 17th, 2006, 08:16 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: trojan keeps returning

Hi,

This may of course have been a FP on Ewidos part ? But if it wasn't it needs eliminating quickly, as proxy.Horst is a nasty. But it sounds like the Run entry etc was very suspicious.

Is your FW set up to ask for permission out for Everything ? If not i would do that.

Reset your System Restore.

I would do some Free online scans here - http://www.kaspersky.com/downloads/kws/kavwebscan.html - http://www.bitdefender.com/scan8/ie.html - BD will delete as well as find.


StevieO
  #5  
Old April 18th, 2006, 08:02 AM
Eldar's Avatar
Eldar Eldar is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: Vilvoorde (Belgium)
Posts: 2,126
Default Re: trojan keeps returning

Quote:
Originally Posted by cliffw
god willin' and the creek don't rise ... this one is gone
You're welcome cliffw.
Nobody wants to have some malware on his system, so I hope it's gone for good.
__________________
Brabantse leeuw | Eendracht maakt macht
Vista HP SP1 | KIS 2009 | Malware Defender | SUPERAntiSpyware
Opera & Firefox | Barca Pro | Sandboxie | FirstDefense-ISR | ShadowProtect
Rogue/Suspect Anti-Spyware Products & Web Sites
  #6  
Old April 25th, 2006, 10:23 AM
shunsho shunsho is offline
Infrequent Poster
 
Join Date: Apr 2006
Posts: 1
Default Re: trojan keeps returning

Hi
This is my first post...
Finally i'm find somebody on the internet that have the same problem that me. I have the same virus of cliffw, and my antivirus (symantec antivirus) detect it. I have a process running named "smss.exe" that i think is the problem. I tried with Mcafee virus scan and anti spyware, and they failed.
I hope that somebody know the solution of the problem.
Thank you.

Quote:
Hi,

This may of course have been a FP on Ewidos part ? But if it wasn't it needs eliminating quickly, as proxy.Horst is a nasty. But it sounds like the Run entry etc was very suspicious.

Is your FW set up to ask for permission out for Everything ? If not i would do that.

Reset your System Restore.

I would do some Free online scans here - http://www.kaspersky.com/downloads/kws/kavwebscan.html - http://www.bitdefender.com/scan8/ie.html - BD will delete as well as find.


StevieO

StevieO: could you write what mean FP and FW? I don't understand your post (sorry my english).

Shunsho of Chile.
  #7  
Old April 25th, 2006, 01:28 PM
TopperID's Avatar
TopperID TopperID is offline
Very Frequent Poster
 
Join Date: Oct 2004
Location: London
Posts: 1,527
Default Re: trojan keeps returning

Quote:
I have a process running named "smss.exe" that i think is the problem.
It might be legitimate:-

http://www.processlibrary.com/direct...smss/index.php

But you need to check the file path, in XP it should be:-

C:\WINDOWS\System32\smss.exe

If you can find it in Explorer you can upload the file to have it checked here:-

http://virusscan.jotti.org/

BTW - FP = False Positive

FW = Fire Wall
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of ewido Support Forums > ewido anti-spyware forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:34 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums