W32/Bagle.C@mm
| W32/Bagle.C@mm |
Destructivity: |
| • Detected by virus detection files published: 2/28/2004 | • Type: Worm |
| • Virus characteristics first published: 2/28/2004 | • Spreading mechanism: |
| • Virus characteristics latest update: 6/9/2004 | • Overall risk: Medium |
| • Alias: | • Payload: Backdoor, terminates AV update processes |
| • Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista |
| Virus type |
Spreading mechanism |
Destructivity and payload |
Additional descriptions |
Detection and removal |
||||||||||
Email characteristics:
When run this worm will copy itself to the Windows System directory using the file name [SYSTEM] eadme.exe. It will also extract and install two other files: [SYSTEM]onde.exe These are additional components of the worm.ONDE.EXE (18944 bytes) contains the main worm functionality, as well as a backdoor. Registry keys created by the worm:HKCUSOFTWAREDateTime2 port = [listen port] The worm contains its own SMTP engine and will send itself to addresses found on the local computer. These addresses are picked from files of type .wab, .txt, .htm, .htm, .dbx, .mdx, .eml, .nch, .mmf, .ods, .cfg, .asp, .php, .pl, .adb and.sht. Mails subjects are composed from the following: Price Attachment is a zip file with a random letter file name. When the worm has installed itself, it will open a Notepad window and exit. |
||||||||||||||