Sophos

Troj/BagleDl-AL

Aliases
  • Email-Worm.Win32.Bagle.ev
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2006 (4.02)
Protection available since 30 November 2005 06:39:18 (GMT)
Last updated 23 December 2005 21:22:50 (GMT)
Detected by All Sophos products

Action

More Information

Troj/BagleDl-AL is a Trojan for the Windows platform.

Troj/BagleDl-AL attempts to remove services, processes, files and registry
entries associated with anti-virus and security software.

When run the Trojan copies itself to the Windows system folder as winlog.exe
and creates a file named winlog.dll in the same folder. Winlog.dll is also
detected as Troj/BagleDl-AL.

The Trojan creates the following registry entries to ensure that it is run each
time a user logs on:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
key2
<System>\winlog.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
key2
<System>\winlog.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer