Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | August 2006 (4.08) |
| Protection available since | 13 February 2006 12:59:15 (GMT) |
| Last updated | 12 July 2006 10:26:36 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Clagger-G is a Trojan for the Windows platform.
Troj/Clagger-G includes functionality to download, install and run new software.
Troj/Clagger-G attempts to download and run http://sterrickfame.com/story.exe.
When Troj/Clagger-G is installed the following files are created:
\1.bat
<Windows>\story.exe
story.exe is detected as Troj/CashGrab-M.
The following registry entries are set, affecting internet security:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FiREWaLLpolicy\StAnDaRDPrOFiLe\AUtHorizedapplications\List
<original path & filename>
<original path & filename>:*:Enabled:MCAFEE_SIGNATURE_HERE_LOL
The Trojan horse has been seen spammed out in emails with the following characteristics:
Subject: Alert:Your personal details was changed!
Message body:
Dear consumer!
You've specified this e-mail as reachable with your credit card online transaction.(your credit card details are not shown here for security reasons) We notify you that your level of authorization has been altered during your last transaction.
Order: 10997210
Date : 11/02/06
Time : 13:10:45
ID : ****7210
You can check the changes details in the attachment.
