Antivirus and Security Software from Sophos

Sophos blogs

Troj/Bagle-TK

Aliases
  • Trojan-Downloader.Win32.Bagle.hr
  • TR/Dldr.Bagle.hu
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 10 January 2008 06:24:14 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Bagle-TK is a Trojan for the windows platform.

Troj/Bagle-TK pretends to be a software crack. When first run it pops up a window asking the user to locate the program to crack. Once the user selects a program the Tojan will return a message saying "Error. Incorrect file version". It also creates a registry entry under

HKCU\Software\FirstRRRun

Troj/Bagle-TK copies itself under <System>\drivers under the name "hidrrr.exe". It also changes the <System>\drivers folder attributes to hidden.

Troj/Bagle-TK drops a rootkit under <System>\drivers\srosa.sys . The dropped file hides the Trojan. This file is also detected as Troj/Bagle-TK.

Troj/Bagle-TK attempts to access a list of hosts on the Internet.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer