Home Malware Programs Trojans Trojan.Bagsu

Trojan.Bagsu

Posted: April 23, 2016

Threat Metric

Threat Level: 8/10
Infected PCs: 14,741
First Seen: April 23, 2016
Last Seen: May 3, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\Microsoft\WindowsUpdate\svchost.exe File name: svchost.exe
Size: 1.33 MB (1333248 bytes)
MD5: eeee6bbf66fff7a48602e8b7d78c3bc9
Detection count: 178
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Microsoft\WindowsUpdate
Group: Malware file
Last Updated: August 9, 2016
%SystemDrive%\Documents and Settings\LocalService\Local Settings\Application Data\NVIDIA Corporation\Update Center\nvdupdate.exe File name: nvdupdate.exe
Size: 94.2 KB (94208 bytes)
MD5: caa0a46f0f6bf5d37e37cb509246dc7f
Detection count: 126
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\LocalService\Local Settings\Application Data\NVIDIA Corporation\Update Center
Group: Malware file
Last Updated: September 8, 2016
%APPDATA%\Mozzilla\csrss.exe File name: csrss.exe
Size: 869.37 KB (869376 bytes)
MD5: 835f5899e48a421e9ee163c264394b68
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Mozzilla
Group: Malware file
Last Updated: August 6, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\WindowsUpdate\VGA.exe%PROGRAMFILES%\NVIDIA Corporation\Update Center\nvdupdate.exe%USERPROFILE%\Microsoft\WindowsUpdate\svchost.exe
Loading...