Skip to main content

Bagle.dldr Trojan runs riot

posted onMarch 2, 2005
by hitbsecnews

Security researchers at antivirus company McAfee have today upped their risk assessment of the Bagle.dldr Trojan, which is spreading rapidly.

The company has raised its assessment after spotting more variants of the worm, and said that its Avert virus response team has received "more than 100 distinct reports of these variants in the wild".

Bagle.dldr is not a mass-mailing threat by itself; it is a downloader which tries to access files from the internet and attempts to disable antivirus and security tools. The Trojan has been used by other Bagle variants, including Bagle.bb, Bagle.bc and Bagle.bd.

After being executed, Bagle.dldr copies itself into the Windows System directory. It drops a file named 'wiwshost.exe' and tries to download a file 'zo2.jpg' from various websites. It also shuts down security services and in some cases renames the main security program executable.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th