Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | October 2008 (4.34) |
| Protection available since | 17 June 2006 14:17:33 (GMT) |
| Last updated | 27 August 2008 21:23:24 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Ranck-EM is a HTTP proxy server Trojan.
Troj/Ranck-EM runs continuously in the background listening on a randomly generated port and allows HTTP traffic to be relayed through the computer.
The Troj/Ranck-EM proxy server may be used to forward spam.
When Troj/Ranck-EM becomes active it sends a notification message to a remote location, specifying the IP address of the current computer and the randomly generated port number which will typically be within the range 10000 - 50000.
Troj/Ranck-EM includes functionality to provide a proxy server.
When first run Troj/Ranck-EM copies itself to <Windows>\winsock\csrss.exe.
Registry entries are set as follows:
HKLM\SOFTWARE\Tmp
Path
<pathname of the Trojan executable>
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
0
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HideFileExt
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCDisable
4
