Sophos

Sophos blogs

Troj/BagleDl-BP

Aliases
  • W32/Bagle.ew
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 30 March 2006 21:49:40 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/BagleDl-BP is a Trojan for the Windows platform.

Troj/BagleDl-BP pretends to be a hacking tool, opening a dialog box with the title "Select file to crack". Whichever file is selected, the Trojan displays the message "Incorrect file version".

The Trojan attempts to download further malicious code. Troj/BagleDl-BP is a Trojan for the Windows platform.

Troj/BagleDl-BP pretends to be a hacking tool, opening a dialog box with the title "Select file to crack". Whichever file is selected, the Trojan displays the message "Incorrect file version".

The Trojan attempts to download further malicious code.

When Troj/BagleDl-BP is installed the following file is created:

<System>\ldr64.dll

This file is also detected as Troj/BagleDl-BP.

The following registry entries are created to run code exported by ldr64.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ldr64
DllName
ldr64.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ldr64
Impersonate
0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ldr64
Startup
Startup

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer