Sophos

Sophos blogs

Troj/CashGrab-T

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
  • Monitors browser activity
Protection available since 8 January 2008 19:40:25 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/CashGrab-T is a Trojan for the Windows platform.

When Troj/CashGrab-T is first run it creates the file <Root>\xp2008.dat, also detected as Troj/CashGrab-T.

The file xpdata2008.dat is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKCR\CLSID\{66F1FDE0-4A1F-450B-A654-EAD08024C500}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66F1FDE0-4A1F-450B-A654-EAD08024C500}

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer