Skip to main content
Skip to main content
Published Feb 06, 2007 | Updated Sep 15, 2017

Worm:Win32/Bagle.ZD@mm

Detected by Microsoft Defender Antivirus

Aliases: Win32/Bagle.EM (CA) Email-Worm.Win32/Bagle.gt (Kaspersky) W32/Bagle.gen (McAfee) W32/Bagle.QS (Norman) W32/Bagle-RC (Sophos) Email-Worm.Win32.Bagle.gt (Sunbelt Software) Trojan.Tooso!gen (Symantec) WORM_BAGLE.JG (Trend Micro)

Summary

Worm:Win32/Bagle.ZD@mm is a mass-mailing e-mail worm that attempts to download and run arbitrary files from remote Web sites. Worm:Win32/Bagle.ZD@mm collects e-mail address from the local drive and also obtains e-mail addresses by checking Web site URLs included in the worm's code. The worm attempts to terminate the Windows Automatic Update service and modifies the System Registry in an attempt to disable booting into Safe Mode.
Follow us