Home Malware Programs Trojans W32/Bagle.dm

W32/Bagle.dm

Posted: May 15, 2006

W32/Bagle.dm is a Trojan designed to disable security related processes and block access to security related sites. W32/Bagle.dm arrives as an email attachment in a .zip format. The name of the infected attachment inside the .zip format will be test.exe, which is a copy of Trojan. Upon execution, the Trojan copies itself as hloader_exe.exe in the Windows System folder and modifies registry to load itself during each startup. W32/Bagle.dm connects to some of the websites in its pre-configured list to check for updates.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 hleader_dll.dll
    2 hloader_exe.exe
Loading...