Threat Database Worms Worm.Bagle.CP

Worm.Bagle.CP

By SpideyMan in Worms

Worm.Bagle.CP is a malicious worm that is delivered through malicious email attachments. Once Worm.Bagle.CP installs on a targeted computer system, it runs its own mail server and sends copies to other email addresses. Worm.Bagle.CP also tries to disable anti-virus software, show pop-up adds and slow down PC performance. Worm.Bagle.CP also will try to download and execute the Mitglieder aka Lohav Trojan which operates a proxy and tries to download malicious files from the Internet. Delete Worm.Bagle.CP immediately after detection to avoid system harm.

SpyHunter Detects & Remove Worm.Bagle.CP

File System Details

Worm.Bagle.CP may create the following file(s):
# File Name MD5 Detections
1. tiridfhe_unpacked.exe
2. hcmhphpg.exe
3. doc.exe
4. bbeagle.exe
5. C:\Windows\System32\.exe
6. windll2.exe
7. Beagle.exe 65848145cc63c8f122b1e22f2b37ba32 0
8. Beagle.exe 69fb9d63022c67fb957a9a4adbb2a31c 0
9. Beagle.exe 5426841c45c8f82f8011ddba6b3ce84b 0
10. Beagle.exe 59711449f1027f5df64021fadaba2985 0
11. Beagle.exe 7d58878f6f4ef458104ec26ca3614bd4 0

Registry Details

Worm.Bagle.CP may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows upgrade"
HKEY_CURRENT_USER\Software\Windows98 "uid"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru1n\erthegdr = "%System%\windll2.exe"
HKEY_CURRENT_USER\Software\Windows98 "frun"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "d3dupdate.exe" = C:\WINNT\System32\bbeagle.exe

Trending

Most Viewed

Loading...