Downloader attempts to disable antivirus and security tools
Downloader attempts to disable antivirus and security tools
R E L A T E D   C O N T E N T
ADVERTISEMENT

Bagle.dldr Trojan runs riot

Security firm ups risk assessment as virus onslaught gathers pace

Steve Ranger, vnunet.com 02 Mar 2005
ADVERTISEMENT

Security researchers at antivirus company McAfee have today upped their risk assessment of the Bagle.dldr Trojan, which is spreading rapidly.

The company has raised its assessment after spotting more variants of the worm, and said that its Avert virus response team has received "more than 100 distinct reports of these variants in the wild".

Bagle.dldr is not a mass-mailing threat by itself; it is a downloader which tries to access files from the internet and attempts to disable antivirus and security tools. The Trojan has been used by other Bagle variants, including Bagle.bb, Bagle.bc and Bagle.bd.

After being executed, Bagle.dldr copies itself into the Windows System directory. It drops a file named 'wiwshost.exe' and tries to download a file 'zo2.jpg' from various websites. It also shuts down security services and in some cases renames the main security program executable.

The virus modifies the file '%WinDir% \system32\drivers\etc\hosts' to prevent the PC from contacting some security websites, and also disables any configured HTTP proxy.

When outgoing TCP connections to port 80 (HTTP) are established, Bagle.dldr tries to download files from a very large list of sites. McAfee said that many of these sites may be decoys as they do not host the file being requested.

See also:

Wurmark-K displays a picture of an albino gorillaMonkey business hides Wurmark-k payload  10 May 2005
Top 10 viruses in February 2005But Bagle and Sober will be the ones to watch  01 Mar 2005
Gone phishingPhishing is becoming ever more prevalent and ever more dangerous  29 Nov 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C# Web Developer, Finance, London Financial Services Required: C#, ASP.NET, AJAX Fantastic opportunity not to be missed!! This is a great opportunity to work on a unique objectives that no other company is doing working ... more >
| JAM Recruitment
Senior Hardware Engineer Scotland/Edinburgh Communication Systems Permanent Position 40-45K+Benefits A leading organisation involved with the design and development of data acquisition systems and synthesis boards for a range of radar, signal intelligence and software radio ... more >
| JAM Recruitment
FPGA Engineer Defence/Safety Critical Buckinghamshire Permanent Position 45K+Benefits A leading UK defence organisation requires an experienced digital design engineer to strengthen its existing development team due to a number of long-term projects that have recently ... more >
| JAM Recruitment
DSP Engineer 3 Months Contract Hertfordshire £Excellent Rates£ This position requires you to have experience of measurement algorithms development for the generation and analysis of digital wireless communication standards including GSM, EDGE, UMTS, WLAN and ... more >
More job opportunities