Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | March 2006 (4.03) |
| Protection available since | 23 January 2006 13:51:48 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Slogger-I is a Trojan for the Windows platform.
Troj/Slogger-I includes functionality to access the internet and communicate with a remote server via HTTP.
Troj/Slogger-I includes email functionality.
When first run Troj/Slogger-I copies itself to <System>\<random filename>.exe and creates the file <System>\<random filename>.dll.
The following registry entry is created to run code exported by the Trojan library on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad
SysTray.Exbr
(6368D1FC-6F5C-4f1b-B164-E67214F678E9)
The file <random filename>.dll is registered as a COM object, creating registry entries under:
HKCR\CLSID\(6368D1FC-6F5C-4f1b-B164-E67214F678E9)
