ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

New Bagle spreads strongly

Published: 20 Jul 2004 08:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new version of the Bagle computer virus started spreading on Monday among PCs connected to the Internet, and antivirus companies warned that more variants are sure to come.

The latest virus, called Bagle.AI by some antivirus companies and Beagle.AG by others, spreads through email as an attached file, which infects a user's PC when opened. The virus is extremely similar to previous versions of the program but uses a different form of compression as a way to dodge virus defences.

"It really looks likes someone took the source code and changed a small number of things and then re-released it," said Oliver Friedrichs, senior manager for antivirus company Symantec's security response team.

Symantec rated the virus as a three on its five-point scale, and rival McAfee called Bagle.AI a medium threat.

The latest Bagle virus is the fourth variation found by antivirus companies in a week. Earlier this month, the program's writer released a version of the virus that contained the source code, the computer commands that can be compiled to make the virus. Antivirus companies believe the move will lead virus writers to create a greater number of variants.

"When the source code is available, it opens up the door to anyone making changes and releasing a new variant," Symantec's Friedrichs said. "It lowers the bar quite dramatically."

Another program with publicly available source code, Agobot, has more than 900 variations.

Bagle.AI arrives in email as an attached file and infects computers running the Windows operating system if the user opens the file. The program harvests email addresses from the infected machine and sends out messages to every address, with itself attached. The "from" field in the email is forged to confuse the source of the message.

Like a previous version, the program also attempts to stop more than 250 security applications from running on the computer and contacts one of nearly 150 German Web sites to let the attackers know of their latest conquest.

The virus also copies itself to any directory that bears a name containing the word "shar," a means of targeting users of peer-to-peer software and to spread across network shares.

Computers compromised by the virus are likely to be open to exploitation by spammers.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
63 out of 112 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Interface Developer

HTML/JS - ODBC - Good analytical and problem solving skills - Excellent communication and presentation skills - Good planning and organisational ...

Senior Technical Support Analyst 35-50k

Phenomenal opportunity to work in the Financial Arena A fast pace leading software house has just released a position. They are seeking an ...

Messaging Support Analyst (AD,TREND protection,Exchange) BANKING

You will be supporting Microsoft Exchange, Windows Server, AD, TREND (virus protection) Blackberry Enterprise Server, MindAlign & Mailmarshal. The ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment