When first run W32/Bagle.EJ opens a file choosing dialog and asks the user:
"Select file to crack"
If a file is selected the following error message is displayed:
"Incorrect file version"
In any case it drops the file ldr64.dll (also detected as W32/Bagle.EJ) into the system folder %WINDIR%\system32 and creates the registry key:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ldr64]
and adds a some values to it in order to be executed at startup.
At next startup the file ldr64.dll is executed in the namespace of winlogon.exe and tries to download the file 444.jpg from several internet addresses and if successful the downloaded file is executed.
|