Troj/BagleDl-AO

Category: Viruses and Spyware
Type: Trojan
Prevalence: Several Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/BagleDl-AO is a Trojan for the Windows platform.

When first run, Troj/BagleDl-AO opens a graphics file named ntimage.gif with the default image viewer.

The latest Bagle Trojan horse open a graphics file when first run

The latest Bagle Trojan horse open a graphics file when first run.

Troj/BagleDl-AO attempts to download files from a number of pre-specified URLs to a file <Windows folder\exefld\<random number>.exe and run it. Troj/BagleDl-AO is a Trojan for the Windows platform.

When first run, Troj/BagleDl-AO opens a graphics file named ntimage.gif with the default image viewer.

The latest Bagle Trojan horse open a graphics file when first run

The latest Bagle Trojan horse open a graphics file when first run.

Troj/BagleDl-AO attempts to download files from a number of pre-specified URLs to a file <Windows folder\exefld\<random number>.exe and run it.

When first run Troj/BagleDl-AO copies itself to <Windows system folder>\anti_troj.exe.

The following registry entries are created to run antiav_exe.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
anti_troj
<Windows system folder>\anti_troj.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
anti_troj
<Windows system folder>\anti_troj.exe

Troj/BagleDl-AO also sets the following registry entry:

HKCU\Software\FirstRRRun
FirstRRRun

download Try Sophos products for free
Download now