Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 8 February 2006 11:01:43 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Ranck-DQ is a backdoor Trojan that allows a remote intruder to route HTTP
traffic through the infected computer.
The following registry entry is created to run Troj/Ranck-DQ on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ihost.exe
<pathname of the Trojan executable>
Troj/Ranck-DQ may also modify the following registry entry:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile
EnableFirewall
Troj/Ranck-DQ when run listens on a randomly chosen TCP port and redirects HTTP
traffic.
