Sophos

Troj/Ranck-BO

Aliases
  • TrojanProxy.Win32.Ranky.ap
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2005 (3.90)
Protection available since 22 December 2004 22:03:02 (GMT)
Detected by All Sophos products

Action

More Information

Sophos's anti-virus products include proactive protection technology, which can defend against new threats without requiring an update. Sophos customers have been protected against Troj/Ranck-BO (detected as Troj/Ranck-Fam) since version 3.89.

Troj/Ranck-BO is a proxy Trojan for the Windows platform.

In order to run on system start, the Trojan creates the following registry
entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
vXCXssdss
<path to EXE>

Troj/Ranck-BO chooses a random port in the range 10000 to 39999 to listen for incoming http requests. The Trojan then attempts to contact several remote sites to register itself with a remote user.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer