Home > Support > Global Security Advisor 

Virus Detail

Win32/Clagger Family

Date Published:
28 Dec 2005

Last Updated:
14 Jan 2007

Threat Assessment

Overall Risk:   Very Low
Wild:  Low
Destructiveness:  High
Pervasiveness:  None

Characteristics

Type : Trojan

Category : Win32

Also known as:  Win32/Clagger!generic, Win32.Clagger.A, Win32.Clagger.AC, Win32.Clagger.AE, Win32.Clagger.AH, Win32/Clagger.AH, Win32.Clagger.AL, Win32.Clagger.B, Win32/Clagger.BF, Win32.Clagger.C, Win32.Clagger.D, Win32.Clagger.E, Win32.Clagger.F, Win32.Clagger.G, Win32.Clagger.H, Win32.Clagger.T!CME934, Win32/Clagger.T!CME934, Win32.Clagger.Z

Immediate Protection Info

 
 
 
 

Description

Win32/Clagger are a family of trojans that download files onto the affected system as well as terminating security related processes. The trojan has been distributed as an FSG-packed, Win32 executable that is between 5000 and 6000 bytes in length.

Back to top

Method of Infection

This trojan does not install itself in any way on an affected system.

Back to top

Payload

Downloads and Executes Arbitrary Files

The trojan's primary function is to download and execute files (including additional malware) from a specific domain that is encrypted in the trojan's code. The domain differs between variants. Variants of this family reported to CA from the wild have used the following domains:


kyee.com
phpwebhosting.com
towarders.com
ukstories.net
toocraft.biz


Files are downloaded to the %Windows% directory using file names contained in the URL. Example file names include:


connect.exe
1.exe
snake.exe
msupdate.exe
91.exe
sev.exe
72.exe


Note: '%Windows%' is a variable location. The malware determines the location of the current Windows folder by querying the operating system. The default installation location for the Windows directory for Windows 2000 and NT is C:\Winnt; for 95,98 and ME is C:\Windows; and for XP is C:\Windows.


At the time of publishing, some of the files known to be downloaded by Clagger are detected as the following trojans by CA antivirus solutions:


  • Win32/Uren.J
  • Win32/Brospy.AB
  • Win32/Sinteri!downloader
  • Win32/Perfips.C

After downloading, Clagger runs a batch file that deletes its executable.


Terminates Processes

The trojan terminates the following processes if they are running on the affected system:


firewall.exe
MpfService.exe
zonealarm.exe
NPROTECT.exe
kpf4gui.exe
atguard.exe
tpfw.exe
kpf4ss.exe
zapro.exe
outpost.exe


Modifies System Settings

The trojan adds its executable to the following reigstry entry so that it can be added as an exception to the Windows Firewall.


HKLM\system\currentControlset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list


Analysis by Amir Fouda


Back to top

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All

Security Resources

 
 
Page Tools