Printer Friendly
The Free Library
14,588,739 articles and books
Member login
User name  
Password 
 
Join us Forgot password?

New version of Bagle widely spammed.


Kaspersky Lab Kaspersky Lab is a computer security company, co-founded by Natalia Kaspersky and Eugene Kaspersky in 1997, offering antivirus, anti-spyware, anti-spam, and anti-intrusion products. , has detected Email-Worm Win32.Bagle.bn. The author of Bagle has been particularly active since the beginning of 2005, releasing a new malicious program every few days. Kaspersky Lab virus analysts have detected two mass mailings of this latest modification, and believe that this latest modification has been spammed in order to maintain the botnets made up of machines infected by Bagle variants.

Fortunately, Bagle.bn is unable to self-replicate. However, this does not mean that the author will not use spammer technologies to mass mail additional copies of the worm.

Bagle.bn arrives as an attachment to infected messages that have a blank subject field and a blank body. The attachment itself is a ZIP file (1) A file that contains one or more files that have been compressed into the ZIP format. Also called a "ZIP archive," "zipped file" or "zipped archive," the ZIP algorithm is the most popular compression method in use.

Not Just the .
, 19KB in size, which contains an EXE file (EXEcutable file) Pronounced "ex-ee file." The name given to a program in machine language that is ready to run in DOS, Windows, OS/2 and VMS. The name comes from the .EXE extension at the end of the program name; for example: XYZ.EXE.  called 19_04_2005.exe Exe (ĕks), river, c.55 mi (90 km) long, rising in the Exmoor, Somerset, SW England, and flowing S across the Cornwall peninsula, past Exeter to the English Channel at Exmouth. .

Once the user launches the executable file, the worm creates a text file in the Windows temporary directory. The file name begins with a tilde A symbol used in Windows, starting with Windows 95, that maintains a short version of a long file or directory name for compatibility with Windows 3.1 and DOS. For example, the short version of a file named "Letter to Joe" would be LETTER~1. Then "Letter to Pat" becomes LETTER~2.  (~) and ends with a .txt extension; the rest of the name consists of randomly generated characters. Bagle.bn uses the default text editor m the infected machine (usually notepad The text editor that comes with Windows. It is a very elementary utility, but gets the job done most of the time. See text editor and WordPad.

(text, tool) Notepad - The very basic text editor supplied with Microsoft Windows.
) to open this file--the user will see the word "Sorry" displayed on screen.

Bagle extracts a file named winshost.exe from its body, saves it to the Windows system directory and registers it in the system registry. This ensures that the worm will be launched each time Windows is rebooted on the infected machine. Bagle.bn will prevent antivirus solutions from being run by deleting a number of system registry values. It also terminates processes connected with some antivirus and firewall applications, and overwrites the hosts file to prevent users of infected machines from viewing antivirus websites.

www.kaspersky.com
COPYRIGHT 2005 A.P. Publications Ltd.
No portion of this article can be reproduced without the express written permission from the copyright holder.
Copyright 2005, Gale Group. All rights reserved. Gale Group is a Thomson Corporation Company.

 Reader Opinion

Title:

Comment:



 

Article Details
Printer friendly Cite/link Email Feedback
Title Annotation:Security
Publication:Software World
Date:May 1, 2005
Words:286
Previous Article:PlanningPME.(Products)(Target Skills of France)(Brief Article)
Next Article:Net EB.(Security)(Brief Article)
Topics:



Related Articles
Netsky--R latest in barrage of warring worms.(Virus Notes)(Brief Article)
New Bagle worm uses old tricks to spread.(News)(Brief Article)
Top ten viruses reported to Sophos in July.(Virus Notes)(Brief Article)
Top ten viruses reported to Kaspersky in July.(Virus Notes)(Brief Article)
MyDoom-S poses as funny photos.(Software Digest)(Brief Article)
Top twenty viruses reported to Kaspersky in August.(Software Digest)(Brief Article)
Top twenty viruses reported to kaspersky in december.(Security Products)
Troj/ Bagle D1-L Trojan horse.(SOFTWARE WORLD DIGEST)(Brief Article)
Security news and products; top tewnty viruses reported to kaspersky in December.(Kaspersky Lab Ltd.)
Virus kidnaps user data.(Security)

Terms of use | Copyright © 2009 Farlex, Inc. | Feedback | For webmasters | Submit articles