Welcome | Log In
Security

New Bagle Virus Making Rounds

Print Version
E-Mail Article
Reprints

Bagle.aq is a mass-mailing threat that contains its own mail engine to construct outgoing e-mail messages. It harvests addresses from local files and then uses the harvested addresses in the "From" field to send itself.


Entering European Markets: A Challenging but Real Opportunity
Although the U.S. has a large Internet population, 79 percent of all Web users are now outside the U.S. Online retailers have viable options for entering into international expansion mode, particularly with respect to European markets. [Download PDF: 6 pgs | 686k]

McAfee More about McAfee today announced that the company's Antivirus and Vulnerability Emergency Response Team (Avert) raised the risk assessment to medium on the recently discovered W32/Bagle.aq@MM, also known as the Bagle.aq worm.

This new variant is a mass-mailing worm that comes in the form of a .zip file. To date, Avert has received more than 150 reports of the virus since its discovery, being stopped or infecting users from the field -- with most of the reports arriving from Brazil, Canada, France, the Netherlands, Taiwan and the United States.

Threat Overview

Bagle.aq is a mass-mailing threat that contains its own mail engine to construct outgoing e-mail messages. It harvests addresses from local files and then uses the harvested addresses in the "From" field to send itself.

This produces a message with a spoofed From address. It contains a remote access component and copies itself to folders that have the phrase "shar" in the name, such as the directories used by common peer-to-peer applications such as KaZaa, Bearshare and Limewire.

The worm sends out a .zip file that contains an HTML and .exe file. The HTML file contains exploit code that, on vulnerable systems, will automatically run the .exe file, which is a downloader Trojan.

Threat Pathology

The downloader Trojan then contacts a large number of remote Web sites to retrieve the virus itself. There is indication in the file that it might also try to password-protect some .zip files.

When the .exe file is run -- either manually or automatically by the HTML file -- it will copy itself to the Windows System directory as windirect.exe.

Once the virus executable is downloaded and run by the downloader Trojan, the virus copies itself into the Windows Consolidate Mac Servers. Run Windows Server on your Mac. Watch a Demo or Download a Trial. System directory as windll.exe.

Social Networking Toolbox:

Print Version E-Mail Article Reprints More by ECT News Security   RSS

Related News Alerts

McAfee Activate Alert | Search Archives

More Stories by ECT News Security

Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
  WiFi Hotspot Locator
City or Zip/Postal Code:
Country/Region:
ECT News Network Information
Locate Products and Services
Corporate
Reader Services
ECT News Network