Troj/BagleDl-AN

Category: Viruses and Spyware
Type: Trojan
Prevalence: Several Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/BagleDl-AN is a Trojan for the Windows platform.

When first run, Troj/BagleDl-AN opens a graphics file named ntimage.gif with the default image viewer.

The latest Bagle Trojan horse open a graphics file when first run

The latest Bagle Trojan horse open a graphics file when first run.

Troj/BagleDl-AN attempts to download files from a number of pre-specified URLs. Troj/BagleDl-AN is a Trojan for the Windows platform.

When first run, Troj/BagleDl-AN opens a graphics file named ntimage.gif with the default image viewer.

The latest Bagle Trojan horse open a graphics file when first run

The latest Bagle Trojan horse open a graphics file when first run.

Troj/BagleDl-AN attempts to download files from a number of pre-specified URLs to the file <Windows\exefld\<random number>.exe and run it.

When first run Troj/BagleDl-AN copies itself to <System>\anti_troj.exe.

The following registry entries are created to run antiav_exe.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
anti_troj
<System>\anti_troj.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
anti_troj
<System>\anti_troj.exe

Troj/BagleDl-AN also sets the following registry entry:

HKCU\Software\FirstRRRun
FirstRRRun

download Try Sophos products for free
Download now