Bagle
Posted: August 23, 2007
Threat Metric
The Threat Meter is a malware assessment that SpywareRemove.com's research team is able to
give every identifiable malware threat. Our Threat Meter includes several criteria based off of
specific malware threats to value their severity, reach and volume. The Threat Meter is able to give
you a numerical breakdown of each threat's initial Threat Level, Detection Count, Volume Count,
Trend Path and Percentage Impact. The overall ranking of each threat in the Threat Meter is a basic
breakdown of how all threats are ranked within our own extensive malware database. The scoring for
each specific malware threat can be easily compared to other emerging threats to draw a contrast in
its particular severity. The Threat Meter is a useful tool in the endeavor of seeking a solution to
remove a threat or pursue additional analytical research for all types of computer users.
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Ranking: | 8,711 |
---|---|
Threat Level: | 8/10 |
Infected PCs: | 10,263 |
First Seen: | July 24, 2009 |
---|---|
Last Seen: | September 29, 2023 |
OS(es) Affected: | Windows |
Bagle is a mass-mailing worm designed to copy itself to the Windows system directory and open a backdoor. Bagle spreads itself as an email attachment and sends messages with the subject 'Hi' and random EXE attachment names. Once executed, Bagle will secretly install a backdoor, which can be used by the remote attacker to get the full control over infected computer.
Aliases
Mal/Generic-A [Sophos]VirTool:Win32/Obfuscator.XX [Microsoft]Generic Packed [McAfee]Trojan-Downloader.Win32.Bagle [Ikarus]PossibleThreat [Fortinet]Suspicious:W32/Malware!Gemini [F-Secure]Trojan.Packed.650 [DrWeb]Heur.Pck.Themida [Comodo]Trojan.Packed-142 [ClamAV]Win32.Trojan.Pakes.4 [CAT-QuickHeal]Win32/Themida [AVG]W32/Heuristic-210!Eldorado [Authentium]Trojan-Downloader.Win32.Bagle!IK [a-squared]Trojan.Win32.Generic!BT [Sunbelt]Troj/Rootkit-FP [Sophos]
More aliases (32)
More aliases (32)
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:CLADD
File name: CLADDSize: 37.37 KB (37376 bytes)
MD5: 3fec608194da830ef2bf6ddde8600a2a
Detection count: 90
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 233.47 KB (233472 bytes)
MD5: b846127773e8e2279f615f7f9105e25f
Detection count: 81
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 233.47 KB (233472 bytes)
MD5: 34862d8cb9c96b8d9f4f6e46cc1b7165
Detection count: 73
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 458.75 KB (458752 bytes)
MD5: 7797047e94859acb061d0479c4ca8262
Detection count: 65
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 233.47 KB (233472 bytes)
MD5: a3a5c57f5ba6eee70f70ebae058244d2
Detection count: 64
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 237.56 KB (237568 bytes)
MD5: f348ffb779ce3df60e2206ac30079354
Detection count: 60
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 233.47 KB (233472 bytes)
MD5: fd022ea0409524f21ae942be1c2555da
Detection count: 53
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 233.47 KB (233472 bytes)
MD5: f17c2520780ebf0f93a37dbcffd4b2bb
Detection count: 51
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 475.13 KB (475136 bytes)
MD5: a2d43af4a5db911ebecfa60c2a7771e3
Detection count: 51
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 225.28 KB (225280 bytes)
MD5: 4cbe8a8514575672c4ed0bb679cc57e2
Detection count: 46
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 233.47 KB (233472 bytes)
MD5: 758ba9c39babee2176548fb14905db44
Detection count: 44
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 466.94 KB (466944 bytes)
MD5: e34275c8b29136d09aa96c67a9dc63c8
Detection count: 44
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 462.84 KB (462848 bytes)
MD5: 8a0e26f77f01aeb0441cd159b605ef22
Detection count: 43
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 237.56 KB (237568 bytes)
MD5: 6033ae81672ff8e173d9c16dd9952e86
Detection count: 42
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 233.47 KB (233472 bytes)
MD5: 81259a4d2b8c5a3d9421970d0c6c42fa
Detection count: 36
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 237.56 KB (237568 bytes)
MD5: 5e7167c60aaa538e748877cb1150078e
Detection count: 34
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 458.75 KB (458752 bytes)
MD5: 3ccbabd647f5f55fbbdd553cc896caf3
Detection count: 22
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 225.28 KB (225280 bytes)
MD5: b935e1dd10997e43aea13c8b37fc429b
Detection count: 21
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 233.47 KB (233472 bytes)
MD5: 72ae627b45c0d02e4c2e8b85655c4cd3
Detection count: 16
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 454.65 KB (454656 bytes)
MD5: e82d0a7caad17084b469d0fb23db5464
Detection count: 13
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 471.04 KB (471040 bytes)
MD5: 950ce462e50a86115f327f111e10acd2
Detection count: 4
Group: Malware file
Last Updated: December 11, 2009
CLADD
File name: CLADDSize: 233.47 KB (233472 bytes)
MD5: 3c1e29a624c3a47fa624997045146874
Detection count: 3
Group: Malware file
Last Updated: December 11, 2009
More files
Registry Modifications
The following newly produced Registry Values are:
Regexp file mask%APPDATA%\Drivers\svchost.exe
Regexp file mask%APPDATA%\Drivers\svchost.exe
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.