Home Malware Programs Worms W32.Bagle.gen

W32.Bagle.gen

Posted: May 24, 2006

W32.Bagle.gen is a member of the W32Bagle family of email worms. W32.Bagle.gen is able to connect with many web sites and send system information to them. In addition, W32.Bagle.gen downloads Block_list.txt from the website and drops it under the system folder. W32.Bagle.gen may disable Windows Firewall on Winxp-Sp2 machine.

W32.Bagle.gen arrives as an email attachment and uses human names as the filenames. The name of the infected attachment may appear as the following:

Edmund.zip
Elizabeth.zip
Fraunces.zip
Grace.zip
Henrie.zip
Jeames.zip

File System Modifications

  • The following files were created in the system:
    # File Name
    1 block_list.txt
    2 regisp32.exe
    3 vcremoval.dll
    4 vcualts32.exe
    5 wimanager.exe
    6 winresw.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run"anti_troj"=C:\WINNT\SYSTEM32\ANTI_TROJ.EXEHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run"anti_troj"=C:\WINNT\SYSTEM32\ANTI_TROJ.EXE

One Comment

  • Timothy Soldo says:

    My new laptop HP ENVY 10 taken over by Win 7 virus and crippled my browers and I have to recover the whole operating and program ll over again. Now it is okay and able to run it. The great thing is tht I did not have any file or picture on it, since I just bought it. It was just a mess to tell you the truth.

Loading...