Home / Spyware Encyclopedia / Proxy.Ranky << Back

Recommendation to Automatically remove Proxy.Ranky


Our products can remove Proxy.Ranky and thousands of other Virus and Spyware automatically and instantly.

Proxy.Ranky Details


  • Category Proxy
  • Discovered 7/13/2006 11:06:00 AM
  • Modified 8/3/2023 5:31:06 PM
  • Threat Level Critical
  • Category Description
    Proxy Trojan turns the victim's computer into a proxy server. This gives the attacker the opportunity to do everything from your computer, including the possibility of conducting credit card fraud and other illegal activities, or even to use system to launch malicious attacks against other networks.

The following Files were created:
VALUEFILESIZECOMPANYNAMEVERSIONSIGNATUREDate
Csay.exe 450560jwh512.0.0.1133e5c8fe73030048582392d7e356cbb 
csrss.exe 25053  fc952822526e5a82d0d1062351201854 
3aa00b55.exe 43590  e4538d31464a65bf76a213e72555a625 
ED9668C7.EXE 21377  e4246020eaf24c72dededb5d7dd984b2 
hzdll.dll 95232  cfc057d041e91bc713d609f8a30ad0c5 
ct2dll.dll 23552  cd180bec485a24b9ab31a1cb567eae98 
5A1B0E70.EXE 53117  bb6fab21db4f2c55aeb044fdb26a64f7 
msvexec32.exe 53117  bb6fab21db4f2c55aeb044fdb26a64f7 
6B6DBBC0.EXE 90115  b38b9e4495ed967e123814e838de8ab3 
Trojan-PSW.Win32.Nilage.ev.exe 61022  8be3c9df5dbba9196cf8a12c75fefe53 

The following Registry Entries were created:
..\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"%WIN.SYS32%\job32.exe"\"%WIN.SYS32%\job32.exe:*:Enabled:Windows Task Scheduler"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Printer Spooler"\"%DAS%\admin\Local Settings\Temp\60f9fd5e.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Anti-Virus Update Scheduler V1.39.12R"\"%DAS%\admin\Local Settings\Temp\245982B0.EXE"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"msll"\"%WIN.SYS32%\MSLL32.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"sysct2"\"%PF%\rundll32.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"scanrig"\"%WIN%\scanrig.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Runtt1"\"%WIN.SYS32%\Internat.exe"
..\Software\Microsoft\Windows\CurrentVersion\RunServices\\"Printer Spooler"\"%DAS.AU.LS%\Temp\ed9668c7.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Printer Spooler"\"%DAS.AU.LS%\Temp\ed9668c7.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"ctfmonn"\"%DAS.AU.LS%\Temp\0feb4c88.exe"

Notice
Please note that the following information is not controlled or endorsed by Max Secure Software. They are captured automatically by tools in our malware Research Lab as a result of executing Spyware Files or browsing Internet in virtual environment. Please contact us if you find any information inappropriate for removal. All the work contained in this report is copyrighted and should not be copied without permission from Max Secure Antivirus. We do not recommend browsing or removing these entries on your own manually. We do not take any warranty against the use or result of the use of this information.

Home / Malware Encyclopedia << Back

Max Total Security can detect & quarantine this Malware