TechShoutAdd to My AOL, MyYahoo, Google, Bloglines



Sophos Warns Internet users of W32/Bagle-KH Worm Targeting Windows

          0 Votes
Friday, June 16th, 2006 | Related entries: Internet, Security

Sophos logo Security giant Sophos has issued a warning for all internet users cautioning them of the W32/bagle-KH worm, which targets Windows users. The worm which has been dubbed as W32/Bagle.gen@MM aswell, is spreading through email attachments. Sophos said it has received several reports of this Win32 worm from the wild.

The W32/Bagle-KH includes functionality to access the Internet and communicate with a remote server via HTTP. When first run W32/Bagle-KH copies itself to [Windows system folder]\hldrrr.exe.

The following registry entries are created to run hldrrr.exe on startup: HKCU\Software\Microsoft\Windows\
CurrentVersion\Run hldrrr [Windows system folder]\hldrrr.exe

HKLM\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run hldrrr [Windows system folder]\hldrrr.exe

Registry entries are created under:
HKCU\Software\FirstRRRun\

For more information and to download the virus identity (IDE) file for W32/Bagle-KH, click here.

Related:


Leave a Reply

*
To prove you're a person (not a spam script), type the security word shown in the picture.
Anti-Spam Image

 
Web TechShout.com