Sophos

Sophos blogs

Troj/Clagger-G

Aliases
  • Downloader.u
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Protection available since 13 February 2006 12:59:15 (GMT)
Last updated 12 July 2006 10:26:36 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Clagger-G is a Trojan for the Windows platform.

Troj/Clagger-G includes functionality to download, install and run new software.

Troj/Clagger-G attempts to download and run http://sterrickfame.com/story.exe.

When Troj/Clagger-G is installed the following files are created:

\1.bat
<Windows>\story.exe

story.exe is detected as Troj/CashGrab-M.

The following registry entries are set, affecting internet security:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FiREWaLLpolicy\StAnDaRDPrOFiLe\AUtHorizedapplications\List
<original path & filename>
<original path & filename>:*:Enabled:MCAFEE_SIGNATURE_HERE_LOL

The Trojan horse has been seen spammed out in emails with the following characteristics:

Subject: Alert:Your personal details was changed!

Message body:

Dear consumer!

You've specified this e-mail as reachable with your credit card online transaction.(your credit card details are not shown here for security reasons) We notify you that your level of authorization has been altered during your last transaction.

Order: 10997210
Date : 11/02/06
Time : 13:10:45
ID : ****7210

You can check the changes details in the attachment.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer