Sophos

Troj/Clicker-CS

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2006 (4.07)
Protection available since 28 May 2006 13:11:51 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Clicker-CS is a Trojan for the Windows platform.

Troj/Clicker-CS includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Clicker-CS copies itself to <Program Files>\winupdates\<original filename>

The following registry entry is created to run Troj/Clicker-CS on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
rmalt
<Program Files>\winupdates\<original filename>

Troj/Clicker-CS disables Regedit and the Task Manager by setting the following registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
DisableRegistryTools

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
DisableTaskMgr

Troj/Clicker-CS also modifies the following registry entry to change the default Microsoft Internet Explorer Start Page:

HKCU\Software\Microsoft\Internet Explorer\Main\
Start Page

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer