Home Malware Programs Adware RankRomp

RankRomp

Posted: December 17, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 21
First Seen: December 18, 2013
Last Seen: September 19, 2020
OS(es) Affected: Windows

RankRomp is adware that may show annoying random advertisements on the computer when the PC user is visiting shopping related and social networking websites. The pop-up advertisements shown by RankRomp may provide computer users with numerous discounts, coupons and offers. If the PC user clicks on the pop-up ads delivered by RankRomp, adware may unwillingly redirect him to unwanted websites. RankRomp may be installed onto Internet Explorer, Mozilla Firefox and Google Chrome while the PC user is installing freeware. Once installed on the computer, RankRomp may modify browser settings and replace the default start page and search service with a suspicious website. When the computer user attempts to search for anything on the Web in any legitimate search provider, he may see the toolbar of RankRomp on the web browser. The toolbar of RankRomp may display a variety of pop-up advertisements and sponsored links related to the computer user's browsing habits. RankRomp may trace the computer user's surfing routine and forward collected data to third-parties for targeted advertising intentions.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Wow6432Node\Microsoft\Tracing\RankRomp_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\RankRomp_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateRankRomp_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateRankRomp_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilRankRomp_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilRankRomp_RASMANCSSYSTEM\ControlSet001\services\eventlog\Application\Update RankRompSYSTEM\ControlSet001\services\eventlog\Application\Util RankRompSYSTEM\ControlSet002\services\eventlog\Application\Update RankRompSYSTEM\CurrentControlSet\services\eventlog\Application\Update RankRompSYSTEM\CurrentControlSet\services\eventlog\Application\Util RankRomp

Additional Information

The following directories were created:
%PROGRAMFILES(x86)%\RankRomp
Loading...