









 |
W32/Bagle.CY Trojan
| Name |
W32/Bagle.CY Trojan |
| Aliases |
Win32.Bagle.CJ@mm, W32/Bagle.cj, Bagle.BI, Win32/Bagle.BI worm |
| Discovered on |
September 19, 2005 |
Virus Information - W32/Bagle.CY Trojan:
W32/Bagle.CY is a trojan. The trojan will infect Windows systems and spreads through email.
This trojan arrives as an email attachment. The name of the infected attachment will be any one of the following;
09_price.zip
new__price.zip
new_price.zip
newprice.zip
price2.zip
price_09.zip
price_new.zip
Upon execution, the trojan copies itself as winshost.exe in the Windows System folder.
The trojan modifies registry at the following location to load itself during each startup.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
This trojan modifies the HOSTS file and tries to terminate some of the security related processes.

|