Security researchers at antivirus company McAfee have today upped their risk assessment of the Bagle.dldr Trojan, which is spreading rapidly.
The company has raised its assessment after spotting more variants of the worm, and said that its Avert virus response team has received "more than 100 distinct reports of these variants in the wild".
Bagle.dldr is not a mass-mailing threat by itself; it is a downloader which tries to access files from the internet and attempts to disable antivirus and security tools. The Trojan has been used by other Bagle variants, including Bagle.bb, Bagle.bc and Bagle.bd.
After being executed, Bagle.dldr copies itself into the Windows System directory. It drops a file named 'wiwshost.exe' and tries to download a file 'zo2.jpg' from various websites. It also shuts down security services and in some cases renames the main security program executable.
The virus modifies the file '%WinDir% \system32\drivers\etc\hosts' to prevent the PC from contacting some security websites, and also disables any configured HTTP proxy.
When outgoing TCP connections to port 80 (HTTP) are established, Bagle.dldr tries to download files from a very large list of sites. McAfee said that many of these sites may be decoys as they do not host the file being requested.
Berkshire, Reading, United Kingdom | Foster Wheeler
InTools/PDS Administrator - Competitive Salary - Reading Foster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil & gas, midstream & LNG, ... more >
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
CMS Engineer - Welwyn Garden CityWho's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at just under ... more >
IT Network and Security Engineer £40,000 per annum The Office of Gas and Electricity Markets (Ofgem) is the regulator for Britain's gas and electricity industries. Our role is to protect consumers and enable them to ... more >
Northampton Borough Council Head of Customer Services and ICT (ref 278) Salary £63k - £73k Team Northampton - Working together for a brighter future The postholder will manage the Customer Services and Information and Communications ... more >More job opportunities