FRISK Software International

W32/Bagle.A@mm rapidly gains momentum.

19 January 2004

W32/Bagle.A@mm is a mass-mailing worm that also behaves like a trojan downloader in its attempts to access remote websites. This is a time-restricted worm and will not execute if the system date has passed the 27th of January 2004.

Bagle.A harvests e-mail addresses from the infected machine's hard drive in order to spread itself further. The worm uses its own SMTP engine to send out e-mails to these harvested addresses and fakes the [From:] address by using another of these harvested addresses. This means that these e-mails can appear to be sent by someone the recipient knows. The subject of these e-mails is normally "Hi", the attachment's name is generated with random characters and the attachment's icon is identical to that of Windows Calculator.

The e-mails sent by Bagle.A are all very similar in structure:

[From:] Forged address
[Subject:] Hi
[Body:]
Test =)
(random character string)
--
Test, yep.
[Attachment] random_name.exe

When first executed the worm runs Windows Calculator to disguise itself while copying itself to the Windows system directory as bbeagle.exe and creating a registry key that enables it to load automatically when the system is started up. If the infected system is connected to the Internet, W32/Bagle.A@mm listens for remote connections and attempts to download and execute a trojan from URL's listed within the worm's body.

For more information on this worm and disinfection please visit our virus information section.

Recommended Reactions

Users are advised to update their virus signature files and make sure they have the latest versions of F-Prot Antivirus installed on their computers.

After updating the virus signature files, users should scan their whole system with the F-Prot Antivirus OnDemand scanner to ensure that their computer security was not compromised before the virus signature files were updated.

For more information on this worm and disinfection please visit our virus information section.

Threat Detection

The latest versions of F-Prot Antivirus detect W32/Bagle.A@mm using virus signature files dated 19 January 2004 or later.

FRISK Software International is a leading developer of anti virus software and anti spam filtering services. FRISK Software International's anti virus computer software, F-PROT Antivirus, is available for a number of operating systems such as Windows, Linux, BSD, Solaris, and AIX as well as the Microsoft Exchange groupware. The company also offers F-PROT AVES, the anti spam and anti virus filtering service.

 
2 February 2010
F-PROT Antivirus Achieves a VB100 Award
F-PROT Antivirus for Unix achieves a VB100 award in the February 2010 issue of Virus Bulletin

11 July 2007
Security Bulletins for July 2007
Microsoft releases six patches this month, three of which are deemed critical

Virus news and information directly to your desktop.


agoat@klaki.net argentina@f-prot.com argentina@frisk.is argentina@complex.is argentina@f-prot.is argentina@frisk-software.com argentina@f-prot.net argentina@f-prot.co.uk brazil@f-prot.com brazil@frisk.is brazil@complex.is brazil@f-prot.is brazil@frisk-software.com brazil@f-prot.net brazil@f-prot.co.uk malta@f-prot.com malta@frisk.is malta@complex.is malta@f-prot.is malta@frisk-software.com malta@f-prot.net malta@f-prot.co.uk a.bjani@f-prot.com a.bjani@frisk.is a.bjani@complex.is a.bjani@f-prot.is a.bjani@f-prot.co.uk a.bjani@frisk-software.com a.bjani@f-prot.net z.fifl@f-prot.com z.fifl@frisk.is z.fifl@complex.is z.fifl@f-prot.is z.fifl@f-prot.co.uk z.fifl@frisk-software.com z.fifl@f-prot.net strumpuri@complex.is strumpure@complex.is strumpuru@complex.is 00a@eircom.net 0maaahonyy@eircom.net 950@eircom.net af@eircom.net am@eircom.net ar@eircom.net as@eircom.net b1@eircom.net boss3@eircom.net ceih@eircom.net cera@eircom.net chxe@eircom.net cs@eircom.net cydw@eircom.net d71@eircom.net dpfy@eircom.net dzuv@eircom.net ehpa@eircom.net epin@eircom.net f1@eircom.net fa@eircom.net fdld@eircom.net fdnv@eircom.net gacg@eircom.net gafj@eircom.net gc@eircom.net gz@eircom.net ha@eircom.net he@eircom.net ia@eircom.net ja@eircom.net k2@eircom.net lleahy6@eircom.net m1@eircom.net no@eircom.net pb@eircom.net qq@eircom.net r6oo@eircom.net ra@eircom.net s2@eircom.net t2@eircom.net ua@eircom.net va@eircom.net vb@eircom.net w2@eircom.net ww2@eircom.net xxxkiss@eircom.net y1@eircom.net ya@eircom.net zz@eircom.net