Troj/BagDl-Gen is a family of multi-component Trojans.
Members of this family generally have a dropper component which drops and loads a DLL component. The DLL component attempts to download and execute files from a remote URL.
Troj/BagDl-Gen is a family of multi-component Trojans.
Members of this family generally have a dropper component which drops and loads a DLL component. The DLL component attempts to download and execute files from a remote URL.
They may copy themselves to the Windows system folder and add a registry entry in the following location to run themselves on system logon or restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Certain members of this family attempt to terminate anti-virus and security-related processes and may also change the HOSTS file to deny access to several anti-virus websites, eg www.sophos.com, www.symantec.com.