Computing.Net > Forums > Security and Virus > New Bagle Worm

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

New Bagle Worm

Reply to Message Icon

Name: IronMan
Date: September 2, 2004 at 03:46:44 Pacific
OS: XP
CPU/Ram: P4 512MB
Comment:


Published in this morning's Register newsletter.
_________________________________________

New Bagle worm drops in and downloads

By John Leyden

A new Bagle dropper and downloader, Bagle-AQ, was bulk mailed to numerous internet users yesterday. The malware arrives in email with subject and email body "foto" and attachment called foto.zip that poses as a file containing photographs.

This zip file contains a HTML file and an executable called foto1.exe. The executable is a dropper. If activated it will kill DLL files related to the updating components of various anti-virus programs. It also attempts download an updated payload every six hours from one of more than 130 separate websites. This payload contains a mass-mailing worm that uses its own SMTP engine to spread. It also opens backdoors on TCP port 80 and UDP port 80, allowing infected computers to be used as email relays. Only Windows machines are affected.

The mode of infection of Bagle-AQ (Trojan downloader) shares more in common with the Download.Ject worm than with previous variants of the Bagle worm. AV firms have confusingly taken to calling it a variety of names from Glieder-H to the BagleDl-A Trojan. Each refers to the same piece of malware. ®



Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


Manually remove SpotOn in... VBS/Redlof-A virus on bra...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: New Bagle Worm

New Bagle targets AV defenses www.computing.net/answers/security/new-bagle-targets-av-defenses/14070.html

New sleeping worm www.computing.net/answers/security/new-sleeping-worm/12855.html

Test, yep >> new email worm www.computing.net/answers/security/test-yep-new-email-worm/8953.html