W32/Bagle.CJ Worm
| Name |
W32/Bagle.CJ Worm |
| Aliases |
WORM_BAGLE.CJ |
| Discovered on |
January 28, 2006 |
Virus Information - W32/Bagle.CJ Worm:
W32/Bagle.CJ is a worm. The worm will infect Windows systems. The worm spreads through email and KaZaA P2P software.
Upon execution, the trojan copies itself as im_2.exe in Windows System folder.
It also drops the following files in Windows Temp folder.
~(random characters).exe
~(random characters).jpg
It opens ~(random characters).jpg file using the default image viewer of the infected system.
The trojan modifies registry at the following location to load itself during each startup.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
It also searches for the folders containing the string share. If it finds the folder it drops the following files in the folder.
ICQ.exe
ICQLite.exe

|