F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : Bagle.L

[Summary] | [Disinfection] | [Detailed Description] | [Detection]



NAME:Bagle.L
ALIAS:I-Worm.Bagle.l, TrojanProxy.Win32.Mitglieder.S, W32/Bagle.L
ALIAS:Mitglieder.S, W32/Bagle.m, Trojan.Mitglieder.C

Summary

Another Bagle worm variant appeared on March 9th, 2004. This variant drops a new Mitglieder proxy trojan variant on an infected computer. Bagle.L does not have its own replication system, so it was most likely spammed using computers where proxy trojans were installed.

Disinfection

F-Secure provides the special disinfection utility to eliminate Bagle.L worm infection. You can download this utility from our ftp site:

ftp://ftp.f-secure.com/anti-virus/tools/f-bagle.exe

ftp://ftp.f-secure.com/anti-virus/tools/f-bagle.zip

Disinfection instructions can be found here:

ftp://ftp.f-secure.com/anti-virus/tools/f-bagle.txt

System administrators who are using F-Secure Policy Manager, can distribute the tool as a JAR package automatically to all workstations.

System administrators can download the JAR version from:

http://www.europe.f-secure.com/tools/f-bagle.jar

ftp://ftp.europe.f-secure.com/anti-virus/tools/f-bagle.jar

Back to the Top


Detailed Description

The worm's file is a PE executable about 14848 bytes in size packed with UPX file compressor. The unpacked file's size is over 47 kilobytes.

When the worm's file is run, it copies itself as IRUN4.EXE file to Windows System folder and creates a startup key for this file in the Registry:

 [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
 "ssgrate.exe" = "%winsysdir%\irun4.exe"

where %winsysdir% represents Windows System folder name.

Then the worm drops 2 more files into Windows System folder: IINJ4.EXE and SYSTEM.EXE. Both files are DLLs (Dynamic Link Libraries). The IINJ4.EXE is a loader for SYSTEM.EXE file. It allows both files to become DLLs used by EXPLORER.EXE file (one of the main Windows components).

The SYSTEM.EXE file is a new variant of Mitglieder proxy trojan. When activated it listens on port 11117 for remote commands and works as a mail relay. The trojan connects to several sites in Germany and Russia to report user's IP address and proxy port. Also the trojan connects to several sites to download a list of banned IP addresses that the proxy will ignore.

Additionally the trojan tries to kill processes that belong to certain anti-virus and security software.

The description of a previous Mitglieder proxy trojan can be found here:

http://www.f-secure.com/v-descs/mitglieder_h.shtml


Back to the Top


Detection

F-Secure Anti-Virus detects Bagle.L and Mitglieder.S in the following update:

[FSAV_Database_Version]

Version=2004-03-09_04

Back to the Top


Technical Details: Alexey Podrezov, March 9th, 2004;

Description Updated: Alexey Podrezov, March 22nd, 2004;

F-Secure Corporation