Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2004 (3.88) |
| Protection available since | 5 November 2004 09:08:14 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Ranck-AY is a proxy Trojan for the Windows platform.
In order to run on system start, the Trojan creates the following registry entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
halloween stream = <path to EXE>
Troj/Ranck-AY chooses a random port in the range 1025 to 33792 to listen for incoming http requests. The Trojan then attempts to contact several remote sites to register itself with a remote user.
Sophos's anti-virus products include proactive protection technology, which can defend against new threats without requiring an update. Sophos customers have been protected against Troj/Ranck-AY (detected as Troj/Ranck-Gen) since version 3.85.
