Malware

Win32/Bagle.J (file analysis)

Malware Removal

The Win32/Bagle.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Bagle.J virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Bagle.J?


File Info:

crc32: 5142E29F
md5: 58f05e9519b3bd825fd6af936f4b2aed
name: 58F05E9519B3BD825FD6AF936F4B2AED.mlw
sha1: be9b785edf541ee1281a39931f7958c031cdccd7
sha256: 16c1391930679d341fea08b889d4dbb3a69d34306cc444b2a628912d10a612c6
sha512: b62875a2899dc40765b63fbee126e669e9bd287439b09470e5f3010d7b697d59b71ba41e0b680b265474e3826f2b60cb4bf65ec0a6376bb44b57d773fb827e96
ssdeep: 192:rTgOHx0lM4MAyRroVbp9+XfP7b3gKgpOywgglV6eIFlihu9nHV2DmOQKdQeHPyJ:l8kyuP7b3gHpzizIGUvSHd5aJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Bagle.J also known as:

BkavW32.AIDetect.malware2
K7AntiVirusEmailWorm ( 004fd25d1 )
Elasticmalicious (high confidence)
DrWebWin32.HLLM.Beagle.596
CynetMalicious (score: 100)
CAT-QuickHealWorm.Bagle
ALYacWorm.Bagle.vx
CylanceUnsafe
ZillyaWorm.Bagle.Win32.202
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Bagle.4b0e1d9c
K7GWEmailWorm ( 004fd25d1 )
Cybereasonmalicious.519b3b
CyrenW32/Bagle.JVBG-2366
SymantecW32.Beagle.J@mm
ESET-NOD32Win32/Bagle.J
APEXMalicious
TotalDefenseWin32/Bagle.J
AvastWin32:Beagle-J [Wrm]
ClamAVWin.Worm.Bagle-44
KasperskyEmail-Worm.Win32.Bagle.i
BitDefenderWin32.Bagle.J@mm
NANO-AntivirusTrojan.Win32.Bagle.frel
ViRobotI-Worm.Win32.Bagle.J
MicroWorld-eScanWin32.Bagle.J@mm
TencentWin32.Worm-email.Bagle.Szlo
Ad-AwareWin32.Bagle.J@mm
SophosMal/Generic-S + W32/Bagle-J
ComodoWorm.Win32.Bagle.J@48wa
BitDefenderThetaAI:FileInfector.3C42486714
VIPRETrojan.Win32.Generic!BT
TrendMicroWORM_BAGLE.GA
McAfee-GW-EditionW32/Bagle.f.j@MM
FireEyeGeneric.mg.58f05e9519b3bd82
EmsisoftWin32.Bagle.J@mm (B)
SentinelOneStatic AI – Malicious PE
JiangminI-Worm/BBEagle.j
WebrootW32.Trojan.Worm-Bagle
AviraWORM/Bagle.J
eGambitUnsafe.AI_Score_96%
KingsoftWorm.Beagle.i.(kcloud)
MicrosoftWorm:Win32/Bagle.J@mm
AegisLabTrojan.Win32.Delf.kZt7
ZoneAlarmEmail-Worm.Win32.Bagle.gen
GDataWin32.Bagle.J@mm
TACHYONWorm/W32.Bagle.22016
AhnLab-V3Worm/Win32.Bagle.R36662
Acronissuspicious
McAfeeW32/Bagle.f.j@MM
MAXmalware (ai score=100)
VBA32MalwareScope.Worm.Scano.1
MalwarebytesMalware.Heuristic.1003
PandaW32/Bagle.J.worm
TrendMicro-HouseCallWORM_BAGLE.GA
RisingWorm.Bagle!8.45 (CLOUD)
YandexTrojan.GenAsa!GgAFFkBuKuU
IkarusMalwareScope.Trojan-PWS.Pinch
MaxSecureTrojan.Malware.1221539.susgen
FortinetW32/Bagle.J@mm
AVGWin32:Beagle-J [Wrm]
Paloaltogeneric.ml
Qihoo-360Win32/Worm.Bagle.HwsBH58A

How to remove Win32/Bagle.J?

Win32/Bagle.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment