Sophos

Troj/Clagger-K

Aliases
  • CME-934
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from May 2006 (4.05)
Protection available since 20 March 2006 12:32:07 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Clagger-K is a Trojan for the Windows platform.

Troj/Clagger-K may be attached to spam messages claiming to be sent from amazon.co.uk.

Troj/Clagger-K includes functionality to download, install and run new software. Troj/Clagger-K is a Trojan for the Windows platform.

Troj/Clagger-K may be attached to spam messages claiming to be sent from amazon.co.uk.

Troj/Clagger-K includes functionality to download, install and run new software.

When Troj/Clagger-K is installed the following files are created:

\1.bat
<Windows>\suhoy112.exe

where 1.bat is used to delete Troj/Clagger-K and suhoy112.exe is the downloaded file.

The following registry entries are set, affecting internet security:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FiREWaLLpolicy\StAnDaRDPrOFiLe\AUtHorizedapplications\List
<pathname of the Trojan executable>
<pathname of the Trojan executable>:*:ENABLED:0

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer