F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : Bagle.EO

[Summary] | [Detailed Description] | [Detection]



NAME:Bagle.EO
ALIAS:W32/Bagle.EO, Trojan-Downloader.Win32.Bagle.d

Summary

This Bagle-related downloader appeared on November 23rd, 2005. It was spammed in e-mails to a large amount of people as 1.EXE. As in previous cases, the downloader was sent inside a ZIP archive.

Detailed Description

When the downloader is run, it copies itself as ANTI_TROJ.EXE file to Windows System folder and creates a startup key for this file in the Registry. Then the downloader tries to download a file from several different sites and to activate it.

Back to the Top


Detection

F-Secure Anti-Virus detects this malware starting from the following update:

[FSAV_Database_Version]

Version=2005-11-23_03

Back to the Top


Writeup: Alexey Podrezov, November 23rd, 2005;

F-Secure Corporation