ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security management Toolkit

Bagle.a: Prevention and cure

Robert Vamosi ZDNet.com

Published: 21 Jan 2004 10:35 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Despite flaws in its programming, a new mass-mailing email worm is spreading across Asia and the Internet. Bagle (Bagle.a@mm) looks like yet another worm designed by spammers, much like Sobig and MiMail. It appears to be building a network of vulnerable computers from which it can later launch anonymous email. When executed, Bagle attempts to email every email address it finds on an infected computer; it will also attempt to download a Trojan horse from a remote site. Bagle appears to be the first of a new family of viruses. Like Sobig, it contains a built-in expiration date; in this case, it's 28 January, 2004. Because Bagle spreads via email and could install a Trojan program, this worm rates a 7/10 on the ZDNet Virus Meter.

How it works
Bagle arrives as an email with the subject line "Hi". It appears to be sent from a random email address. The body text reads "Test =)" followed by random letters. The attached file, too, uses random letters followed by an .exe extension. The attached file may use the Windows calculator icon.

When executed, the worm will collect email addresses from address books, text, and HTML files. The worm will not, however, contact addresses using the following domains:

.r1
@hotmail.com
@msn.com
@microsoft
@avp

After 28 January, 2004, Bagle will not execute.

According to iDefense, Bagle will make the following changes to the system Registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run d3update.exe=WINDOWS SYSTEM DIRECTORY\bbeagle.exe

HKU\%SystemInfo%\Software\Microsoft\Windows\CurrentVersion\Run d3update.exe=WINDOWS SYSTEM DIRECTORY\bbeagle.exe

HKCU\Software\Windows98 frun=1 uid=RANDOMIZED VALUE

Bagle also attempts to download a Trojan from a remote site. To do so, it attempts to communicate on port 6777. Desktop firewalls should be able to detect and stop this activity. In theory, this downloaded Trojan would allow the virus author at some future date to update or modify the worm. At this time, however, all the sites Bagle attempts to contact appear to be inactive.

Removal
A few antivirus companies have updated their signature files to include this worm. This will stop the infection upon contact and in some cases will remove an active infection from your system. For more information, see Central Command, Computer Associates, F-Secure, McAfee, MessageLabs, Norman, Sophos, Symantec and Trend Micro.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
83 out of 193 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Senior Support Analyst - Leeds - 30,000

Senior Support Analyst (Active Directory/ Windows 2003 Server/ SQL) - Leeds, West Yorkshire Senior Support Analyst required by my client based in the ...

ACTIVE DIRECTORY/EXCHANGE NETWORK ENGINEER - 35K

Your technical skills should include: - Strong Active Directory - Exchange - Citrix A basic understanding of VMWare and SAN would be most beneficial ...

Helpdesk Support Analyst (1st/2nd Line Support)

The key skills, experience, and knowledge criteria for this vacancy include: - A high degree of resilience and the ability to operate with precision ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec