Sophos

Sophos blogs

W32/Bagle-IV

Aliases
  • Email-Worm.Win32.Scano.t
  • W32/Scano.H
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email attachments
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 4 May 2006 02:36:59 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Bagle-IV is a mass-mailing worm and backdoor Trojan for the Windows platform.

W32/Bagle-IV includes functionality to access the internet and communicate with a remote server via HTTP. W32/Bagle-IV is a mass-mailing worm and backdoor Trojan for the Windows platform.

W32/Bagle-IV includes functionality to access the internet and communicate with a remote server via HTTP.

When first run W32/Bagle-IV copies itself to <Windows>\csrss.exe and creates the file <Temp>\Message.zip.

The file Message.zp is detected as W32/Bagle-Zip.

The following registry entry is changed to run W32/Bagle-IV on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe
Debugger
<Windows>\csrss.exe

W32/Bagle-IV will attempt to email itself to addresses harvested from the infected computer as an attachment.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer