TrojanDownloader:Win32/Bagle.gen!A is the generic detection for trojans that download worms from the
Win32/Bagle family. They are usually distributed as attachments of spammed e-mail messages.
Installation
Upon execution, TrojanDownloader:Win32/Bagle.gen!A may display a message or perform an action on the system in an attempt to fool the user that it is not malicious.
TrojanDownloader:Win32/Bagle.gen!A may arrive in the system as an attachment to spammed e-mail messages. The attachment is usually a ZIP archive that contains one or more files, among which is the malicious executable detected as TrojanDownloader:Win32/Bagle.gen!A. Some examples of ZIP names are:
La cave du sommelier 1.27.zip
Launch Internet Explorer Browser.zip
StudioSchool Pro 3.3.zip
Xtreme_Xtractor_Pro_2.1__With_Crack_.zip
ad-aware - anniversary edition 8.0.5.zip
audiofan_wave_to_mp3_converter_1.1.zip
The malicious executable names may include, but is not limited to, the following:
crac.exe
crack.exe
install.exe
install_crack.exe
install_patch.exe
install_patch_1.exe
key_gen.exe
keygen.exe
keygenerator.exe
patch.exe
run.exe
serial.exe
setup.exe
setup_3.exe
The other files that may be included in the ZIP archive are usually of the following types:
- TXT (text files)
- DLL (dynamic link library files)
- NFO (ASCII information files)
However, these files usually contain junk data.
TrojanDownloader:Win32/Bagle.gen!A creates the following registry subkeys and entries as part of its installation routine:
Adds value: "frstrunn"
With data: "1"
To subkey: HKCU\Software\bisoft
Adds value: "EnableLUA"
With data: "<value>"
To subkey: HKLM\SOFTWARE\Microsoft\Windows\Security Center\Svc
where <value> is a certain number.
Adds key: HKCU\Software\Local AppWizard-Generated Applications
and all its associated subkeys.
It may also create the following folders:
- %AppData%\drivers
- %AppData%\drivers\downld
Payload
Modifies system settings
TrojanDownloader:Win32/Bagle.gen!A may attempt to disable the "administrator in Admin Approval Mode" user type for the system:
Modifies value: "EnableLUA"
With data: "0"
To subkey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
Downloads and executes other malware
TrojanDownloader:Win32/Bagle.gen!A may download and execute other malware in the system, particularly malware belonging to the
Win32/Bagle family.
Additional Information
Some systems infected with TrojanDownloader:Win32/Bagle.gen!A may become unstable.
Analysis by Patrik Vicol