Sophos

Troj/Ranck-AZ

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2004 (3.88)
Protection available since 10 November 2004 10:00:07 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Ranck-AZ is a Proxy Trojan for the Windows platform that allows a malicious user to route HTTP traffic through remote access to an infected computer.

Troj/Ranck-AZ may arrive as a part of RAR archive that is a W32/Sdbot-RF dropper file.

When executed Troj/Ranck-AZ sets the following registry entry with the path to the running file in order to run automatically when Windows starts up:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\vxcxcvfck.

Also Troj/Ranck-AZ sets the registry entry:

HKLM\SOFTWARE\Microsoft\DownloadManager

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer