Content
W32/Bagle.gen@MM!9725
- Type
- Virus
- SubType
- Downloader
- Discovery Date
- 11/23/2005
- Length
- 9,725 bytes
9,219 bytes - Minimum DAT
- 4635 (11/23/2005)
- Updated DAT
- 4635 (11/23/2005)
- Minimum Engine
- 5.1.00
- Description Added
- 11/23/2005
- Description Modified
- 11/23/2005 9:04 AM (PT)
Tab Navigation
Characteristics
Several new W32/Bagle downloader variants have been widely spammed to users (November 23, 2005). To date, they are detected as W32/Bagle.gen@MM with the 4635 DATs.
These are downloader trojans. However, like previous Bagle variants, it is likely that in the near future, the author(s) will post an accompanying EXE file on a remote server, which SPAMs new versions of Bagle (not to addresses harvested on the local system, but to addresses specified in spam lists also on remote web servers). This trojan was mass-spammed in a ZIP attachment and uses peoples names as the filenames, for example:
- Edmund.zip
- Elizabeth.zip
- Fraunces.zip
- Grace.zip
- Henrie.zip
- Jeames.zip
Symptoms
When run, the trojan copies itself into the Windows system directory as ANTI_TROJ.EXE, for example:
- C:\WINNT\SYSTEM32\ANTI_TROJ.EXE
The following Registry key is added to hook system startup:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Run "anti_troj" = C:\WINNT\SYSTEM32\ANTI_TROJ.EXE - HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Run "anti_troj" = C:\WINNT\SYSTEM32\ANTI_TROJ.EXE
This trojan then contacts several websites and attempts to download a PHP file. The domains contacted are as follows:
- 25kadr.org
- charlies-truckerpage.de
- template.nease.net
- s89.tku.edu.tw
- phrmg.org
- www.etwas-mode.de
- www.rewardst.com
- 757555.ru
- www.8ingatlan.hu
- oklens.co.jp
- www.a2zhostings.com
- www.abavitis.hu
- abtechsafety.com
- acentrum.pl
- www.adamant-np.ru
- furdoszoba.info
- adavenue.net
- ccooaytomadrid.org
- abtechsafety.com
- av2026.comex.ru
- 80.146.233.41
- www.barth.serwery.pl
- www.leap.co.il
- virt33.kei.pl
- www.bmswijndepot.com
- 209.126.128.203
- www.timecontrol.com.pl
- adoptionscanada.ca
- 65.108.195.73
- tkdami.net
- www.ubu.pl
- adventecgroup.com
- sacafterdark.net
- agenciaspublicidadinternet.com
- www.agroturystyka.artneo.pl
- kepter.kz
- ahava.cafe24.com
- mijusungdo.net
- aibsnlea.org
- aikidan.com
- 202.44.52.38
- drinkwater.ru
- ala-bg.net
- allinfo.com.au
- eleceltek.com
- alevibirligi.ch
- alfaclassic.sk
- allanconi.it
- www.americarising.com
- americasenergyco.com
- amerykaameryka.com
- amistra.com
- analisisyconsultoria.com
- calamarco.com
Method of Infection
These Bagle-related downloaders are known to have been widely spammed to users as email attachments. When executed, the victim machine is infected.
Removal
All Users:
Use specified engine and DAT files for detection and removal.
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Characteristics
Characteristics -
Several new W32/Bagle downloader variants have been widely spammed to users (November 23, 2005). To date, they are detected as W32/Bagle.gen@MM with the 4635 DATs.
These are downloader trojans. However, like previous Bagle variants, it is likely that in the near future, the author(s) will post an accompanying EXE file on a remote server, which SPAMs new versions of Bagle (not to addresses harvested on the local system, but to addresses specified in spam lists also on remote web servers). This trojan was mass-spammed in a ZIP attachment and uses peoples names as the filenames, for example:
- Edmund.zip
- Elizabeth.zip
- Fraunces.zip
- Grace.zip
- Henrie.zip
- Jeames.zip
Symptoms
Symptoms -
When run, the trojan copies itself into the Windows system directory as ANTI_TROJ.EXE, for example:
- C:\WINNT\SYSTEM32\ANTI_TROJ.EXE
The following Registry key is added to hook system startup:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Run "anti_troj" = C:\WINNT\SYSTEM32\ANTI_TROJ.EXE - HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Run "anti_troj" = C:\WINNT\SYSTEM32\ANTI_TROJ.EXE
This trojan then contacts several websites and attempts to download a PHP file. The domains contacted are as follows:
- 25kadr.org
- charlies-truckerpage.de
- template.nease.net
- s89.tku.edu.tw
- phrmg.org
- www.etwas-mode.de
- www.rewardst.com
- 757555.ru
- www.8ingatlan.hu
- oklens.co.jp
- www.a2zhostings.com
- www.abavitis.hu
- abtechsafety.com
- acentrum.pl
- www.adamant-np.ru
- furdoszoba.info
- adavenue.net
- ccooaytomadrid.org
- abtechsafety.com
- av2026.comex.ru
- 80.146.233.41
- www.barth.serwery.pl
- www.leap.co.il
- virt33.kei.pl
- www.bmswijndepot.com
- 209.126.128.203
- www.timecontrol.com.pl
- adoptionscanada.ca
- 65.108.195.73
- tkdami.net
- www.ubu.pl
- adventecgroup.com
- sacafterdark.net
- agenciaspublicidadinternet.com
- www.agroturystyka.artneo.pl
- kepter.kz
- ahava.cafe24.com
- mijusungdo.net
- aibsnlea.org
- aikidan.com
- 202.44.52.38
- drinkwater.ru
- ala-bg.net
- allinfo.com.au
- eleceltek.com
- alevibirligi.ch
- alfaclassic.sk
- allanconi.it
- www.americarising.com
- americasenergyco.com
- amerykaameryka.com
- amistra.com
- analisisyconsultoria.com
- calamarco.com
Method of Infection
Method of Infection -
These Bagle-related downloaders are known to have been widely spammed to users as email attachments. When executed, the victim machine is infected.
Removal -
Removal -
All Users:
Use specified engine and DAT files for detection and removal.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A