Home Malware Programs Trojans Bagle

Bagle

Posted: August 23, 2007

Threat Metric

Ranking: 8,711
Threat Level: 8/10
Infected PCs: 10,263
First Seen: July 24, 2009
Last Seen: September 29, 2023
OS(es) Affected: Windows

Bagle is a mass-mailing worm designed to copy itself to the Windows system directory and open a backdoor. Bagle spreads itself as an email attachment and sends messages with the subject 'Hi' and random EXE attachment names. Once executed, Bagle will secretly install a backdoor, which can be used by the remote attacker to get the full control over infected computer.

Aliases

Mal/Generic-A [Sophos]VirTool:Win32/Obfuscator.XX [Microsoft]Generic Packed [McAfee]Trojan-Downloader.Win32.Bagle [Ikarus]PossibleThreat [Fortinet]Suspicious:W32/Malware!Gemini [F-Secure]Trojan.Packed.650 [DrWeb]Heur.Pck.Themida [Comodo]Trojan.Packed-142 [ClamAV]Win32.Trojan.Pakes.4 [CAT-QuickHeal]Win32/Themida [AVG]W32/Heuristic-210!Eldorado [Authentium]Trojan-Downloader.Win32.Bagle!IK [a-squared]Trojan.Win32.Generic!BT [Sunbelt]Troj/Rootkit-FP [Sophos]
More aliases (32)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



CLADD File name: CLADD
Size: 37.37 KB (37376 bytes)
MD5: 3fec608194da830ef2bf6ddde8600a2a
Detection count: 90
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 233.47 KB (233472 bytes)
MD5: b846127773e8e2279f615f7f9105e25f
Detection count: 81
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 233.47 KB (233472 bytes)
MD5: 34862d8cb9c96b8d9f4f6e46cc1b7165
Detection count: 73
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 458.75 KB (458752 bytes)
MD5: 7797047e94859acb061d0479c4ca8262
Detection count: 65
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 233.47 KB (233472 bytes)
MD5: a3a5c57f5ba6eee70f70ebae058244d2
Detection count: 64
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 237.56 KB (237568 bytes)
MD5: f348ffb779ce3df60e2206ac30079354
Detection count: 60
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 233.47 KB (233472 bytes)
MD5: fd022ea0409524f21ae942be1c2555da
Detection count: 53
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 233.47 KB (233472 bytes)
MD5: f17c2520780ebf0f93a37dbcffd4b2bb
Detection count: 51
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 475.13 KB (475136 bytes)
MD5: a2d43af4a5db911ebecfa60c2a7771e3
Detection count: 51
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 225.28 KB (225280 bytes)
MD5: 4cbe8a8514575672c4ed0bb679cc57e2
Detection count: 46
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 233.47 KB (233472 bytes)
MD5: 758ba9c39babee2176548fb14905db44
Detection count: 44
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 466.94 KB (466944 bytes)
MD5: e34275c8b29136d09aa96c67a9dc63c8
Detection count: 44
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 462.84 KB (462848 bytes)
MD5: 8a0e26f77f01aeb0441cd159b605ef22
Detection count: 43
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 237.56 KB (237568 bytes)
MD5: 6033ae81672ff8e173d9c16dd9952e86
Detection count: 42
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 233.47 KB (233472 bytes)
MD5: 81259a4d2b8c5a3d9421970d0c6c42fa
Detection count: 36
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 237.56 KB (237568 bytes)
MD5: 5e7167c60aaa538e748877cb1150078e
Detection count: 34
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 458.75 KB (458752 bytes)
MD5: 3ccbabd647f5f55fbbdd553cc896caf3
Detection count: 22
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 225.28 KB (225280 bytes)
MD5: b935e1dd10997e43aea13c8b37fc429b
Detection count: 21
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 233.47 KB (233472 bytes)
MD5: 72ae627b45c0d02e4c2e8b85655c4cd3
Detection count: 16
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 454.65 KB (454656 bytes)
MD5: e82d0a7caad17084b469d0fb23db5464
Detection count: 13
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 471.04 KB (471040 bytes)
MD5: 950ce462e50a86115f327f111e10acd2
Detection count: 4
Group: Malware file
Last Updated: December 11, 2009
CLADD File name: CLADD
Size: 233.47 KB (233472 bytes)
MD5: 3c1e29a624c3a47fa624997045146874
Detection count: 3
Group: Malware file
Last Updated: December 11, 2009

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\Drivers\svchost.exe

Related Posts

Loading...