W32/Bagle.CN Trojan
| Name |
W32/Bagle.CN Trojan |
| Aliases |
W32/Bagle.cn |
| Discovered on |
September 19, 2005 |
Virus Information - W32/Bagle.CN Trojan:
W32/Bagle.CN is an trojan. The trojan will infect Windows systems and spreads through email.
This trojan arrives as an email attachment. The name of the infected attachment will be;
price_new.zip
This file contains price_20.exe which is a copy of trojan.
Upon execution, the trojan copies itself as winshost.exe in the Windows System folder.
It also drops a file wiwshost.exe in the Windows System folder.
The trojan modifies registry at the following location to load itself during each startup.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
This trojan connects to some of the websites in its pre-configured list and downloads osa6.gif.
It also tries to terminate some of the security related processes.

|