Sophos

Troj/Ranck-AY

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2004 (3.88)
Protection available since 5 November 2004 09:08:14 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Ranck-AY is a proxy Trojan for the Windows platform.

In order to run on system start, the Trojan creates the following registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
halloween stream = <path to EXE>

Troj/Ranck-AY chooses a random port in the range 1025 to 33792 to listen for incoming http requests. The Trojan then attempts to contact several remote sites to register itself with a remote user.

Sophos's anti-virus products include proactive protection technology, which can defend against new threats without requiring an update. Sophos customers have been protected against Troj/Ranck-AY (detected as Troj/Ranck-Gen) since version 3.85.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer