









 | W32/Bagle.BQ Trojan| Name | W32/Bagle.BQ Trojan | | Aliases | Email-Worm.Win32.Bagle.BQ , Troj/BagleDl-R | | Discovered on | 27th June, 2005 |
Virus Information - W32/Bagle.BQ Trojan:
W32/Bagle.BQ is a downloader trojan. This will infect Windows systems.
The trojan arrives as an attachment along with an email in a compressed format .zip
The infected email carries a spoofed 'From' address picked up randomly from the infected system.
The subject and the body of the infected email will be blank.
The infected email carries any one of the following infected attachment;
new.zip
original.zip
Upon execution of the infected attachment, the trojan copies itself as winshost.exe and wiwshost.exe in the Windows System folder.
It alters the windows registry at the following location to load itself during next startup;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The trojan also tries to terminate the processes related to some security softwares.
It also prevents the user to access some of the security related websites.

|