Home arrow News arrow Computers arrow Uno más: Bagle.GX
English Spanish French German Italian Portuguese
Uno más: Bagle.GX
Image

PandaLabs has informed about lots of a worm variants, which affects many PCs around the world, and leave them defenceless since one of the functions of Bagle is to deactivate the firewall and antvirus.

Full Name: Worm.W32/Bagle.GX@MM  
Type: E-mail worm.
Plataform: [W32] Portable Executables .EXE, .SCR, .DLL de Windows de 32 bits: 95, 98, Me, NT, 2000, XP y 2003.
Compressed size (bytes): 94126
Alias: WORM_BAGLE.GX by Trend Micro), W32/Bagle.fb!pwdzip by McAfee y
W32.Beagle.FG@mm by por Symantec.

In it first execution, it creates the following files in the system:

hidn.exe (copy of itself)

m_hook.sys (rootkit component)

error.gif (element without importance)

temp.zip (copy of itself)

It generates a key in the register to restart its operations together with Windows:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]"drv_st_key" = "%UserProfile%\Application Data\hidn\hidn.exe"

Other entries are generated to support its operations:

[HKEY_CURRENT_USER\Software\FirstRuxzx]"FirstRun" = "1"

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\m_hook]

[HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_M_HOOK]

It diminishes the stability to the start system through the elimination of the following register:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot]

Note: %UserProfile% equals to C:\Documents and Settings\[user's name] for Windows 2000/XP/NT.

It shuts up the different process belonging to antiviral and firewall utilities and it also starts its hiding process in its rootkit component:

wuauserv
Aavmker4
ABVPN2K
ADBLOCK.DLL
ADFirewall AFWMCL
AntiyFirewall
ARP.DLL aswTdi
avast! Antivirus
avast! Mail Scanner
avast! Web Scanner
AVEService
AVExch32Service
AvFlt Avg7Alrt
Avg7Core
AvgCore
AvgFsh AVGFwSrv
AVIRAMailService
AVIRAService
awhost32
backweb client-4476822
BackWeb Client - 7681197
backweb client-4476822
Bdfndisf
bdftdif
bdss
BlackICE
BsFileSpy
ccSetMgr
ccSetMgr.exe
CONTENT.DLL
ewido security suite control
ewido security suite driver
ewido security suite guard
F-Prot Antivirus Update Monitor
F-Secure Gatekeeper Handler Starter
firewall
FSFW
FSMA
FTPFILT.
DLL
DLL
HTTPFILT.DLL
KAVMonitorService
KAVSvc
McAfeeFramework
McShield
McTaskManager
mcupdmgr.exe
NDIS_RD
Network Associates Log Service
nipsvc
Norman Type-R
Norman ZANDA
Norton AntiVirus Server
nvcoas
Personal Firewall
POP3FILT.DLL
PREVSRV
ravmon8
SECRET.DLL
SharedAccess
SweepNet
SWEEPSRV.SYS
Symantec AntiVirus Client
Symantec Core LC
tmtdi
tm_cfw
Vba32ECM
Vba32ifs
VisNetic AntiVirus Plug-in
vrfwsvc
vsmon
xcommWith

Its Simple Mail Transfer Protocol, it resends itself to all e-mail addresses found in the extensions with the following extensions:

wab
txt
msg
htm
shtm
stm
xml
dbx
mbx
mdx
cfg
asp
php
pl
wsh
adb
tbb
sht
jsp

It avoids be resent to e-mail addresses with the following strings:

rating@
f-secur
news
feste
gold-certs@
help@
info@
nobody@
noone@
kasp
admin
icrosoft
sopho
winzip
abuse
panda
cafee
spam
pgp

Through the TCP25 port, the Bagle.GX will try to establish connection with SMTP servers to send messages, for example:

smtp.google.com

Read more...


 

Search

 

spacer.png, 0 kB
Copyright © 2006 Eazel. All rights reserved. spacer.png, 0 kB