Sophos

Troj/Bagle-AS

Aliases
  • Email-Worm.Win32.Bagle.ev
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2006 (4.02)
Protection available since 30 November 2005 06:39:18 (GMT)
Last updated 23 December 2005 21:22:50 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bagle-AS is a backdoor Trojan.

When the Trojan executes it will start a backdoor and send connection information to a number of websites. Troj/Bagle-AS is a backdoor Trojan.

When the Trojan executes it will start a backdoor on a random port in the range
2000 to 50000. The Trojan tries to send connection information to a number of
websites.

It copies itself to the Windows system folder as wintems.exe. The Trojan also
sets creates the following registry entry so that it is started on user logon:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
german.exe
<System>\wintems.exe

The following registry entries are also created

HKCU\Software\DateTime4\uid
HKCU\Software\DateTime4\port
HKCU\Software\DateTime4\wdrn

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer