Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | February 2006 (4.02) |
| Protection available since | 30 November 2005 06:39:18 (GMT) |
| Last updated | 23 December 2005 21:22:50 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/BagleDl-AL is a Trojan for the Windows platform.
Troj/BagleDl-AL attempts to remove services, processes, files and registry
entries associated with anti-virus and security software.
When run the Trojan copies itself to the Windows system folder as winlog.exe
and creates a file named winlog.dll in the same folder. Winlog.dll is also
detected as Troj/BagleDl-AL.
The Trojan creates the following registry entries to ensure that it is run each
time a user logs on:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
key2
<System>\winlog.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
key2
<System>\winlog.exe
