Home / malwarePDF  

Email-Worm:W32/Bagle.HR


First posted on 11 April 2007.
Source: SecurityHome

Aliases :

Email-Worm:W32/Bagle.HR is also known as Trojan.Tooso.R, Email-Worm.Win32.Bagle.hr, Win32.Bagle.HK@mm, Win32/Bagle.HP.

Explanation :

Email-Worm:W32/Bagle.HR is a trojan-downloader with rootkit technology.

Upon executing Email-Worm:W32/Bagle.HR for the first time it shows the following dialog box as a decoy:



It will display the same message regardless of the file chosen.

In order to check itself for first execution, Email-Worm:W32/Bagle.HR checks the following registry entry:


If the said registry entry is available it will no longer show the dialog box.

Email-Worm:W32/Bagle.HR drops copies of itself in the following path and filename:


It also drops the following rootkit driver to hide its malicious activities:


To enable automatic execution upon boot, it adds the following auto start entry but waits for 300000 ms before adding it:
It also adds its rootkit driver component as a service by adding the following changes to the registry:


Email-Worm:W32/Bagle.HR deletes the following key in order to prevent the user from booting into safemode:


Email-Worm:W32/Bagle.HR downloads other malware from the following links:


The rootkit driver terminates and deletes the following files that are related to antivirus software:

Last update 11 April 2007

 

TOP

Malware :

Family: