Content

W32/Bagle.gen!F7B43CAC

Type
Virus
SubType
E-mail
Discovery Date
12/22/2005
Length
9,042 bytes
Minimum DAT
4656 (12/22/2005)
Updated DAT
4656 (12/22/2005)
Minimum Engine
5.1.00
Description Added
12/22/2005
Description Modified
12/22/2005 10:02 PM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This threat will be detected as W32/Bagle.gen with the 4656 DAT files.

This is a downloader trojan. However, like previous Bagle variants, it is likely that in the near future, the author(s) will post an accompanying EXE file on a remote server, which SPAMs new versions of Bagle (not to addresses harvested on the local system, but to addresses specified in spam lists also on remote web servers). This trojan was mass-spammed in a ZIP attachment and uses peoples names as the filenames:

e.g.

  • Edmund.zip
  • Elizabeth.zip
  • Fraunces.zip
  • Grace.zip
  • Henrie.zip
  • Jeames.zip

Symptoms

When run, the trojan copies itself into the Windows system directory as ANTI_TROJ.EXE, for example:

  • C:\WINNT\SYSTEM32\ANTI_TROJ.EXE

The following Registry key is added to hook system startup:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\ CurrentVersion\Run "anti_troj" = C:\WINNT\SYSTEM32\ANTI_TROJ.EXE
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\ CurrentVersion\Run "anti_troj" = C:\WINNT\SYSTEM32\ANTI_TROJ.EXE

The following Registry key is also added:

  • HKEY_CURRENT_USER\Software\FirstRRRun

This trojan then contacts several websites and attempts to download a [hidden].PHP file. The domains contacted are as follows:

  • 202.44.52.38
  • 209.126.128.203
  • 65.108.195.73
  • 80.146.233.41
  • abtechsafety.com
  • acentrum.pl
  • ahava.cafe24.com
  • aibsnlea.org
  • aikidan.com
  • ala-bg.net
  • alevibirligi.ch
  • alfaclassic.sk
  • allanconi.it
  • allinfo.com.au
  • americasenergyco.com
  • amerykaameryka.com
  • amistra.com
  • analisisyconsultoria.com
  • calamarco.com
  • drinkwater.ru
  • eleceltek.com
  • kepter.kz
  • mijusungdo.net
  • virt33.kei.pl
  • www.150m.com
  • www.adamant-np.ru
  • www.americarising.com
  • www.bakelit.hu
  • www.batlground.com
  • www.bbrealservis.sk
  • www.befag.ru
  • www.benininfo.com
  • www.bennylife.com
  • www.bestcheapdomainregistration.info
  • www.bidsforbaby.com
  • www.binhaigolf.com
  • www.biotenk.com
  • www.bitsolution.ro
  • www.boldrussell.com
  • www.bronko-m.ru
  • www.bulkemaildirectmarketing.com
  • www.bulkemailservicenow.com
  • www.calidad.biz
  • www.cansew.ca
  • www.cansultdubai.ae
  • www.casaquecanta.com
  • www.casino-malibu.ru
  • www.chilotitomarino.cl
  • www.chinaculturedpearl.com
  • www.colin18.com
  • www.connectesl.com
  • www.encansbelec.com
  • www.khonkaenpoc.com
  • www.leap.co.il
  • www.nmtltd.com
  • www.nuclear.com.pl
  • www.ubu.pl
  • www.vnettools.com

The [hidden].PHP file may contain an encoded version of the virus. When decoded, the file is detected as W32/Bagle.gen .

Method of Infection

These Bagle-related downloaders are known to have been widely spammed to users as email attachments. When executed, the victim machine is infected.

Removal

Detection is included in our BETA DAT files and will also be included in the next scheduled DAT release. In addition to the DAT version requirements for detection, the specified engine version (or greater) must also be used.

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Characteristics

Characteristics -

This threat will be detected as W32/Bagle.gen with the 4656 DAT files.

This is a downloader trojan. However, like previous Bagle variants, it is likely that in the near future, the author(s) will post an accompanying EXE file on a remote server, which SPAMs new versions of Bagle (not to addresses harvested on the local system, but to addresses specified in spam lists also on remote web servers). This trojan was mass-spammed in a ZIP attachment and uses peoples names as the filenames:

e.g.

  • Edmund.zip
  • Elizabeth.zip
  • Fraunces.zip
  • Grace.zip
  • Henrie.zip
  • Jeames.zip

Symptoms

Symptoms -

When run, the trojan copies itself into the Windows system directory as ANTI_TROJ.EXE, for example:

  • C:\WINNT\SYSTEM32\ANTI_TROJ.EXE

The following Registry key is added to hook system startup:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\ CurrentVersion\Run "anti_troj" = C:\WINNT\SYSTEM32\ANTI_TROJ.EXE
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\ CurrentVersion\Run "anti_troj" = C:\WINNT\SYSTEM32\ANTI_TROJ.EXE

The following Registry key is also added:

  • HKEY_CURRENT_USER\Software\FirstRRRun

This trojan then contacts several websites and attempts to download a [hidden].PHP file. The domains contacted are as follows:

  • 202.44.52.38
  • 209.126.128.203
  • 65.108.195.73
  • 80.146.233.41
  • abtechsafety.com
  • acentrum.pl
  • ahava.cafe24.com
  • aibsnlea.org
  • aikidan.com
  • ala-bg.net
  • alevibirligi.ch
  • alfaclassic.sk
  • allanconi.it
  • allinfo.com.au
  • americasenergyco.com
  • amerykaameryka.com
  • amistra.com
  • analisisyconsultoria.com
  • calamarco.com
  • drinkwater.ru
  • eleceltek.com
  • kepter.kz
  • mijusungdo.net
  • virt33.kei.pl
  • www.150m.com
  • www.adamant-np.ru
  • www.americarising.com
  • www.bakelit.hu
  • www.batlground.com
  • www.bbrealservis.sk
  • www.befag.ru
  • www.benininfo.com
  • www.bennylife.com
  • www.bestcheapdomainregistration.info
  • www.bidsforbaby.com
  • www.binhaigolf.com
  • www.biotenk.com
  • www.bitsolution.ro
  • www.boldrussell.com
  • www.bronko-m.ru
  • www.bulkemaildirectmarketing.com
  • www.bulkemailservicenow.com
  • www.calidad.biz
  • www.cansew.ca
  • www.cansultdubai.ae
  • www.casaquecanta.com
  • www.casino-malibu.ru
  • www.chilotitomarino.cl
  • www.chinaculturedpearl.com
  • www.colin18.com
  • www.connectesl.com
  • www.encansbelec.com
  • www.khonkaenpoc.com
  • www.leap.co.il
  • www.nmtltd.com
  • www.nuclear.com.pl
  • www.ubu.pl
  • www.vnettools.com

The [hidden].PHP file may contain an encoded version of the virus. When decoded, the file is detected as W32/Bagle.gen .

Method of Infection

Method of Infection -

These Bagle-related downloaders are known to have been widely spammed to users as email attachments. When executed, the victim machine is infected.

Removal -

Removal -

Detection is included in our BETA DAT files and will also be included in the next scheduled DAT release. In addition to the DAT version requirements for detection, the specified engine version (or greater) must also be used.

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A