Trojan-Downloader.Win32.Bagle.cu
From Total Malware Info
Trojan program that downloads and installs other software into system without user’s notice. It is windows PE-EXE file. The size of component varies from 200 to 320 kilobytes. Packed with PE-Ninja.
Installation
Copies own executable file as:
%System%\drivers\hidr.exe
Drops from its body a rootkit driver:
%System%\drivers\srosa.sys
Creates a system service called ”Megadrv3”, which auto-loads the rootkit each time Windows starts.
Then creates the following registry entries:
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] drvsyskit=%System%\drivers\hidr.exe
So the worm executable would now be launched every time the windows starts.
Payload
Using own rootkit driver trojan hides its files on the hard drive and entries in the system registry, also trojan removes its process from the task manager’s list.
Terminates processes with the following names:
a2cmd.exe a2guard.exe a2HiJackFree.exe a2scan.exe a2service.exe a2start.exe a2upd.exe a2wizard.exe aavshield.exe About.exe AckWin32.exe ADVCHK.EXE Agb5.exe Agb5_.exe AhnSD.exe airdefense.exe ALERTSVC.EXE ALMon.exe ALOGSERV.EXE ALsvc.exe ALUNOTIFY.EXE amon.exe Anti-Trojan.exe AntiVirScheduler AntiVirService AntiVirus.exe ANTS.EXE APVXDWIN.EXE Armor2net.exe ash.exe ashAvast.exe ashAvSrv.exe ashchest.exe ashDisp.exe ashDug.exe ashEnhcd.exe ashLogV.exe ashMaiSv.exe ashPopWz.exe ashQuick.exe ashServ.exe ashsimp2.exe ashSimpl.exe ashSkPcc.exe ashSkPck.exe ashUpd.exe ashWebSv.exe ash_UpdateMediator.exe aswRegSvr.exe aswUpdSv.exe ATCON.EXE ATUPDATER.EXE ATWATCH.EXE AUPDATE.EXE AUTODOWN.EXE AutostartExplorer.exe AUTOTRACE.EXE AUTOUPDATE.EXE avadmin.exe avcenter.exe avciman.exe avcmd.exe avconfig.exe Avconsol.exe AVENGINE.EXE avgamsvr.exe avgcc.exe AVGCC32.EXE AVGCTRL.EXE avgdiag.exe avgemc.exe avgfwsrv.exe avginet.exe avgnpdln.exe avgnpsvc.exe AVGNT.EXE avgntdd avgntmgr avgrssvc.exe avgscan.exe AVGSERV.EXE AVGUARD.EXE avgupden.exe avgupsvc.exe avgvv.exe avgw.exe avgwizfw.exe avinitnt.exe AvkServ.exe AVKService.exe AVKWCtl.exe avnotify.exe AVP.EXE AVP32.EXE avpcc.exe avpm.exe AVPUPD.EXE avscan.exe AVSCHED32.EXE avsynmgr.exe AVWUPD32.EXE AVWUPSRV.EXE AVXMONITOR9X.EXE AVXMONITORNT.EXE AVXQUAR.EXE BackWeb-4476822.exe bdagent.exe bdmcon.exe bdnews.exe bdoesrv.exe bdss.exe bdsubmit.exe bdsubmitwiz.exe BDSurvey.exe bdswitch.exe bdwizreg.exe blackd.exe blackice.exe blindman.exe BTIni.exe BTIniNT.exe cafix.exe CavApp.exe CaVasm.exe CavAUD.exe CavEmSrv.exe Cavmr.exe CavMUD.exe Cavoar.exe CavQ.exe CAVSCons.exe cavse.exe CavSn.exe CavSub.exe CAVSubmit.exe CavUMAS.exe CavUserUpd.exe Cavvl.exe ccApp.exe ccEvtMgr.exe ccProxy.exe ccSetMgr.exe CEmRep.exe CFIAUDIT.EXE CHKDSK.EXE clamscan.exe ClamTray.exe ClamWin.exe Claw95.exe Claw95cf.exe cleaner.exe cleaner3.exe CliSvc.exe CMain.exe CMGrdian.exe copyx64.exe cpd.exe cssexc.exe custinstall.exe custsetup.exe defensewall.exe DefWatch.exe dislite.exe DOORS.EXE dpatrolq.exe drvctl.exe DrVirus.exe DrvMap.exe drwadins.exe drweb32w.exe drweb386.exe drwebscd.exe DRWEBUPW.EXE drwebwcl.exe drwreg.exe ecmd.exe egni.exe ekrn.exe EMM386.EXE ESCANH95.EXE ESCANHNT.EXE ewidoctrl.exe exit_av.exe EzAntivirusRegistrationCheck.exe F-AGNT95.EXE F-PROT95.EXE F-Sched.exe F-StopW.EXE FAMEH32.exe FAST.EXE FCH32.exe firebird.exe FireSvc.exe FireTray.exe FIREWALL.EXE FLOPPY.EXE FLOPPY9x.EXE FLOPPYME.EXE FPAVServer.exe fpavupdm.exe FProtTray.exe fpscan.exe fptrayproc.exe FPWin.exe freshclam.exe FRW.EXE fsample.exe fsaua.exe fsauach.exe fsav.exe fsav32.exe fsavaui.exe fsavgui.exe fsavstrt.exe fsavwsch.exe fsavwscr.exe fsbwsys.exe fsdbuh.exe fsdc.exe fsdfwd.exe FSDIAG.exe FsDiagUi.exe fsfwwsch.exe fsfwwscr.exe fsgetwab.exe fsgk32.exe fsgk32st.exe fsguidll.exe fsguiexe.exe FSHDLL32.exe fshelp.exe FSHOTFIX.exe fsihcomp.exe fsihs.exe FSIMAGE.EXE FSLAUNCH.exe FSM32.exe FSMA32.exe FSMB32.exe fspc.exe fspex.exe fsqh.exe fssf.exe fssg.exe fssm32.exe fsstm.exe fssw.exe fstlui.exe fsuninst.exe fsus.exe gcasDtServ.exe gcasServ.exe GIANTAntiSpywareMain.exe GIANTAntiSpywareUpdater.exe GUARD.EXE guardgni.exe GUARDGUI.EXE GuardNT.exe helper.exe hipsdiag.exe HRegMon.exe Hrres.exe HSockPE.exe HUpdate.EXE iamapp.exe iamserv.exe ICLOAD95.EXE ICLOADNT.EXE ICMON.EXE ICSSUPPNT.EXE ICSUPP95.EXE ICSUPPNT.EXE IERegFix.exe IFACE.EXE ih8.exe ih8run.exe ILAUNCHR.exe INETUPD.EXE InocIT.exe InoRpc.exe InoRT.exe InoTask.exe InoUpTNG.exe InstallCAVS.exe InstallLicense.exe InstallLSP.exe InstLsp.exe INWISE.EXE IOMON98.EXE isafe.exe ISATRAY.EXE ISPNews.exe isPwdsvc.exe ISRV95.EXE ISSVC.exe isUAC.exe JEDI.EXE KAV.exe kavmm.exe KAVPF.exe KavPFW.exe KAVStart.exe KAVSvc.exe KAVSvcUI.EXE KMailMon.EXE KPfwSvc.EXE KWatch.EXE licmgr.exe livesrv.exe LiveUpdate.exe LOCKDOWN2000.EXE LogWatNT.exe lpfw.exe LUALL.EXE LUCallbackProxy.exe LUCheck.exe LUCOMSERVER.EXE LuComServer_3_2.EXE LuConfig.exe LUInit.exe Luupdate.exe MalwareRemoval.exe MCAGENT.EXE mcmnhdlr.exe mcregwiz.exe Mcshield.exe MCUPDATE.EXE mcvsshld.exe MemString.exe MINILOG.EXE MONITOR.EXE monlite.exe MonSysNT.exe MOOLIVE.EXE MpEng.exe mpssvc.exe MSMPSVC.exe mva.exe MVC.exe myAgtSvc.exe myagttry.exe navapsvc.exe NAVAPW32.EXE NavLu32.exe NAVStub.exe NAVW32.EXE Navwnt.exe NDD32.EXE NeoWatchLog.exe NeoWatchTray.exe NetstatViewer.exe nisoptui.exe NISSERV NISUM.EXE NMAIN.EXE nod32.exe nod32krn.exe nod32kui.exe NORMIST.EXE NotifyHA.exe notstart.exe npavtray.exe NPFMNTOR.EXE npfmsg.exe NPROTECT.EXE NSCHED32.EXE NSMdtr.exe NssServ.exe NssTray.exe ntoskrnl.exe ntrtscan.exe NTXconfig.exe NUPGRADE.EXE NVC95.EXE Nvcod.exe Nvcte.exe Nvcut.exe NWCDEX.EXE NWService.exe oasrv.exe oaui.exe OfcPfwSvc.exe olAddin.exe OnAccessInstaller.exe osCheck.exe OUTPOST.EXE PartIn.exe PartIn9x.exe partinfo.exe PartInNT.exe PAV.EXE PavFires.exe PavFnSvr.exe Pavkre.exe PavProt.exe pavProxy.exe pavprsrv.exe pavsrv51.exe PAVSS.EXE pccguide.exe PCCIOMON.EXE pccntmon.exe PCCPFW.exe PcCtlCom.exe PCTAV.exe PERSFW.EXE pertsk.exe PERVAC.EXE PM8Flash.exe PMagic.exe PMagic9x.exe PMagicBT.exe PMagicNT.exe PNMSRV.EXE POLUTIL.exe POP3TRAP.EXE POPROXY.EXE postinstall.exe ppfw.exe PQBOOT.EXE Pqboot32.exe PQBOOTX.EXE pqbw.exe PQLAUNCH.EXE PQMAGIC.EXE PqPe.exe pqpe9x.exe pqpent.exe preconfig.exe preupd.exe prevsrv.exe PrevxSetup.exe ProcessViewer.exe psctrls.exe pshost.exe PsImSvc.exe PTEDIT.EXE PTEDIT32.EXE PTEPIT32.EXE PXAgent.exe PXConsole.exe PXL.exe PXL1.exe PXReset.exe pxsupport.exe QHM32.EXE QHONLINE.EXE QHONSVC.EXE QHPF.EXE qhwscsvc.exe qklez.exe qrtfix.exe quaranti.exe RavMon.exe RavTimer.exe Realmon.exe REALMON95.EXE register.exe removeit.exe Remover.exe Rescue.exe rfwmain.exe Rtvscan.exe RTVSCN95.EXE RuLaunch.exe RunSetup.exe sarcli.exe sargui.exe SAV32CLI.EXE SAVAdminService.exe SAVMain.exe savprogress.exe SAVScan.exe SCAN32.EXE scanner.exe ScanningProcess.exe sched.exe sdhelp.exe sdinvoker.exe sdloader.exe SDTrayApp.exe seccenter.exe SERVIC~1.EXE SHSTAT.EXE sigtool.exe SiteCli.exe smc.exe SNDSrvc.exe SNUTIL.EXE SPBBCSvc.exe SPHINX.EXE spiderml.exe spidernt.exe Spiderui.exe sporder.exe SpybotSD.exe SPYXX.EXE SS3EDIT.EXE start_diag.exe stopsignav.exe SubmitFiles.exe svcntaux.exe swAgent.exe swdoctor.exe swdsvc.exe SWNETSUP.EXE SymantecRootInstaller.exe symlcsvc.exe SymProxySvc.exe SymSPort.exe SymWSC.exe SYNMGR.EXE Sysinfo.exe TAUMON.EXE TBMon.exe TC.EXE tca.exe TCM.EXE TDS-3.EXE TeaTimer.exe TFAK.EXE tgsvcstp.exe THAV.EXE THGnard.exe THSM.EXE Tmas.exe tmlisten.exe Tmntsrv.exe TmPfw.exe tmproxy.exe tnbutil.exe tracelog.exe TRJSCAN.EXE TrojanGuarder.exe TrojanHunter.exe trtddptr.exe uiscan.exe UninstallCAVS.exe Uninstaller.exe UninstallLSP.exe unp_test.exe Up2Date.exe UPDATE.EXE UpdaterUI.exe updclient.exe upgrepl.exe UPSObMaker.exe UUpd.exe Vba32ECM.exe Vba32ifs.exe vba32ldr.exe Vba32PP3.exe VBSNTW.exe vchk.exe vcrmon.exe VetTray.exe viritexp.exe viritsvc.exe VirusKeeper.exe VirusNews.exe VistAux.exe VisthLic.exe VisthUpd.exe VPTRAY.EXE vrfwsvc.exe VRMONNT.EXE vrmonsvc.exe vrrw32.exe VSECOMR.EXE Vshwin32.exe vsmon.exe vsserv.exe VsStat.exe w9xpopen WATCHDOG.EXE Wclose.exe webfiltr.exe WebProxy.exe Webscanx.exe WEBTRAP.EXE WGFE95.EXE wil.exe Winaw32.exe WindowList.exe winroute.exe winss.exe winssnotify.exe WRADMIN.EXE WRCTRL.EXE writespid.exe WRPROG.EXE wsctool.exe xcommsvr.exe zatutor.exe ZAUINST.EXE zauninst.exe zlclient.exe zonealarm.exe _AVP32.EXE _AVPCC.EXE _AVPM.EXE
Stops and deletes the following Anti-Virus program’s services:
wuauserv Aavmker4 ABVPN2K ADBLOCK.DLL ADFirewall AFWMCL Ahnlab task Scheduler alerter AlertManger AntiVir Service AntiyFirewall ARP.DLL aswMon2 aswRdr aswTdi aswUpdSv Ati HotKey Poller avast! Antivirus avast! Mail Scanner avast! Web Scanner AVEService AVExch32Service AvFlt Avg7Alrt Avg7Core Avg7RsW Avg7RsXP Avg7UpdSvc AvgCore AvgFsh AVGFwSrv AvgFwSvr AvgServ AvgTdi AVIRAMailService AVIRAService avpcc AVUPDService AVWUpSrv AvxIni awhost32 backweb client 4476822 BackWeb Client 7681197 backweb client-4476822 Bdfndisf bdftdif bdss BlackICE BsFileSpy BsFirewall BsMailProxy CAISafe ccEvtMgr ccPwdSvc ccSetMgr ccSetMgr.exe CONTENT.DLL DefWatch DNSCACHE.DLL drwebnet dvpapi dvpinit ewido security suite control ewido security suite driver ewido security suite guard F-Prot Antivirus Update Monitor F-Secure Gatekeeper Handler Starter firewall fsbwsys FSDFWD FSFW FSMA FSAUA F-Secure Gatekeeper Handler Starter FTPFILT.DLL FwcAgent fwdrv Guard NT HSnSFW HSnSPro HTMLFILT.DLL HTTPFILT.DLL IMAPFILT.DLL InoRPC InoRT InoTask Ip6Fw Ip6FwHlp KAVMonitorService KAVSvc KLBLMain KPfwSvc KWatch3 KWatchSvc MAILFILT.DLL McAfee Firewall McAfeeFramework McShield McTaskManager mcupdmgr.exe MCVSRte Microsoft NetWork FireWall Services MonSvcNT MpfService navapsvc Ndisuio NDIS_RD Network Associates Log Service nipsvc NISSERV NISUM NNTPFILT.DLL NOD32ControlCenter NOD32krn NOD32Service Norman NJeeves Norman Type-R Norman ZANDA Norton AntiVirus Server NPDriver NPFMntor NProtectService NSCTOP nvcoas NVCScheduler nwclntc nwclntd nwclnte nwclntf nwclntg nwclnth NWService OfcPfwSvc Outbreak Manager Outpost Firewall OutpostFirewall PASSRV PAVAGENTE PavAtScheduler PAVDRV PAVFIRES PAVFNSVR Pavkre PavProc PavProt PavPrSrv PavReport PAVSRV PCCPFW PCC_PFW PersFW Personal Firewall POP3FILT.DLL PREVSRV PROTECT.DLL PSIMSVC qhwscsvc wscsvc Quick Heal Online Protection ravmon8 RfwService SAVFMSE SAVScan SBService schscnt SECRET.DLL SharedAccess SmcService SNDSrvc SPBBCSvc SpiderNT SweepNet SWEEPSRV.SYS Symantec AntiVirus Client Symantec Core LC The_Hacker_Antivirus Tmntsrv TmPfw tmproxy tmtdi tm_cfw T_H_S_M V3MonNT V3MonSvc Vba32ECM Vba32ifs Vba32Ldr Vba32PP3 VBCompManService VexiraAntivirus VFILT VisNetic AntiVirus Plug-in vrfwsvc vsmon VSSERV WinAntivirus WinRoute WinDefend wuauserv xcomm
Downloads files from from the following URLs:
http://cor***asdoncarlos.com.ar/hld.php http://www.co***esloges.com/hld.php http://aytocrist***l.com/hld.php http://***datumiembro.com/hld.php http://cyc***olf.com/hld.php http://cyclet***.de/hld.php http://***eironsclimb.com/hld.php http://www.***aining.ee/hld.php http://dadiv***a.com/hld.php http://dancef***uency.com.br/hld.php http://darioo.*****vista.org/hld.php http://darul***aa.com/hld.php http://datalife***ter.com/hld.php http://da***sa.com/hld.php http://www.db**tric.com/hld.php http://WWW.***.COM.PE/hld.php http://www.deb***k.com/hld.php http://dec***rogil.es/hld.php http://delatt***.com/hld.php http://demi***iello.com.ar/hld.php http://demo.po***ltapejara.com/hld.php http://derechoyde***racia.es/hld.php http://www.de***go.com/hld.php http://de***te.nl/hld.php http://diepp***inemaritime.com/hld.php http://digitalp***ure.com/hld.php http://digi***mo.com/hld.php http://diocese****ec.qc.ca/hld.php http://div****lub.com/hld.php http://divinoj****yn.***er***ta.org/hld.php http://dj***roz.com/hld.php http://djsop***o.cp.win.pl/hld.php http://djthefox.com/hld.php http://deniselinsconvites.com.br/hld.php http://lo***.org/hld.php http://oliwia.***ierka.org/hld.php http://dospa***s.es/hld.php http://dponcemi.***ervista.org/hld.php http://dru***ast.com.pl/hld.php http://du***.bx.pl/hld.php http://duk***m.com/hld.php http://d**esi****udio.com/hld.php http://eas***mo.es/hld.php http://doct*****e.org/hld.php http://ecce***.es/hld.php http://eco***.be/hld.php http://www.ed****llage.it/hld.php http://programase******vos-salamanca.com/hld.php http://www.ek****s.pl/hld.php http://www.e****p.pl/hld.php http://ele****ris.com/hld.php http://e*****.pl/hld.php http://e****n.pl/hld.php http://pa******.co.uk/hld.php http://www.elo****.com/hld.php http://elpa*****n.es/hld.php http://indu****asca*********obledo.com/hld.php http://www.e******oup.cz/hld.php http://ener****port.com/hld.php http://epamat******andez.com/hld.php http://era***o100.**********.org/hld.php http://e****t.com/hld.php http://espac******n.org/hld.php http://www.espacep************juif.fr/hld.php http://www.eszter*******haz.hu/hld.php http://www.etal******oy.ru/hld.php http://www.ex******nt.lv/hld.php http://st********s.com/hld.php http://www.fa******ws.com/hld.php http://fal******om.18.****.ru/hld.php http://www.concr******masa.com/hld.php http://fer******arie.e**********ces.com/hld.php http://fe***********iano.com/hld.php http://f****s.org.br/hld.php http://wolfs*******rt.be/hld.php http://filibertovi***********juelo.com/hld.php http://f********er.com/hld.php http://www.fit***.com/hld.php http://fi***k.fi.f***ic.org/hld.php http://f***s.net/hld.php http://fome*******ito.es/hld.php http://fort****f.h***.pl/hld.php http://fo****tur.com/hld.php http://foua******a.com/hld.php http://foxx.fa*****es.org/hld.php http://fr*********eber.com/hld.php http://fr*******lean.ch/hld.php http://www.kfzei*********vice.de/hld.php http://www.aut******uche.de./hld.php http://www.s********ces.co.uk/hld.php http://www.b***s.at/hld.php http://www.musi**********osswallstadt.de/hld.php http://tri******elt.de/hld.php http://www.wei********gerich.de/hld.php http://www.ten*********ine.de/hld.php http://www.a******p.com/hld.php http://www.k****s.cz/hld.php http://g****i.sk/hld.php http://galat**********ismo.com/hld.php http://ga*****ol.com/hld.php http://www.ga******as.co.il/hld.php http://robe*********es.co.nz/hld.php http://gaz*******lna.edu.pl/hld.php http://g***.si/hld.php http://gen******n80.be/hld.php http://www.geor******zle.ch/hld.php http://gi*******co.com/hld.php http://gi***.***.pl/hld.php http://gires*********dasi.org.tr/hld.php http://girmant*******graphy.com/hld.php http://gi**********ura.org/hld.php http://gl*****a.com.pl/hld.php http://***.***.97.63/hld.php http://br*****a.v24.pl/hld.php http://go********r.pl/hld.php http://go*****e.com/hld.php http://go*****ru.21.****.ru/hld.php http://gr******e.gr.******.org/hld.php http://www.greg******ermark.com/hld.php http://grupo******iona.com/hld.php http://gr*****lpe.com/hld.php http://ospk****no.b****.net.pl/hld.php http://3g-tec*******tries.com/hld.php http://gui***********enis.com/hld.php http://gui********na.com/hld.php http://gui********na.com/hld.php http://gui*****.com/hld.php http://gui**************o-pene.com/hld.php http://gui********************nis.com/hld.php http://gui********in.com/hld.php http://je********ls.boo.pl/hld.php http://gus*********nca.com/hld.php http://g****.net/hld.php http://www.ha*********ting.co.uk/hld.php http://haw*******y.com/hld.php http://hel*****d.net/hld.php http://www.hel*****d.net/hld.php http://hostal*********2.com/hld.php http://hosta*********o.com/hld.php
and stores them in the following folder:
%WinDir%\exefqd
with random names that consist of series of digits and have .exe extension. When downloaded these files are launched by the trojan.
Trojan creates the following registry key to store configuration data:
[HKCU\Software\FirstRRRun]
Removal instructions
- Reboot your windows in safe mode
- Remove the following files:
%System%\drivers\srosa.sys %System%\drivers\hidr.exe
- Using Task Manager terminate the trojan process.
- Delete the original trojan file (its file name and location depends on the way the trojan originally penetrated the target computer).
- Delete the following parameter in registry key:
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] drvsyskit=%System%\drivers\hidr.exe
- Delete registry key:
[HKCU\Software\FirstRRRun]
- Remove the following folder and delete all files stored in it:
%WinDir%\exefqd





