I-Worm.Bagle.e
Description I-Worm.Bagle.e This worm spreads via the Internet as a file attached to infected emails. The worm itself is a PE EXE file of approximately 17KB, packed using PEX. The unpacked file is approximately 27KB in size. Infected messages have the following characteristics: Message header (chosen from the list below): Accounts department Ahtung! Camila Daily activity report Ello! Flayers among us Freedom for everyone From Hair-cutter From me Greet the day Hardware devices price-list Hello my friend Hi! Jenny Jessica Looking for the report Maria Melissa Monthly incomings summary New Price-list Price Price list Pricelist Price-list Proclivity to servitude Registration confirmation The account The employee The summary USA government abolishes the capital punishment Weekly activity report Wellall You are dismissed You really love me? he he Message body (chosen from the list below): Cya Empty Everything inside the attach Look it through Request Response Subj Attachment: The attachment is a zip file which a name consisting of a random combination of a, b, and c (e.g. cdda.zip). Inside the .zip file is an .exe file with a random name, containing a text file icon. Installation Following installation, the worm copies itself and its components to the Windows system directory, under the names "i1ru74n4.exe", "godo.exe", "ii455nj4.exe", and "i1ru74n4.exeopen". It registers "i1ru74n4.exe" in the system registry auto-run key: [HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun] "rate.exe" = "%system%i1ru74n4.exe" The worm also creates the registry key: [HKCUSOFTWAREDateTime4] and saves its variables in the key. The worm attempts to connect to several sites and save information about the infected victim computer on these sites. The worm also creates a mutex imain_mutex to flag its presence in memory. Propagation The worm searches for files with the following extentions: adb asp cfg dbx eml htm html mdx mmf nch ods php pl sht txt wab harvests email addresses, and then sends itself to all addresses found. To send messages, the worm uses its own SMTP server. Remote administration The worm opens port 2745 and tracks port activity. The backdoor function makes it possible to remotely execute commands and download files to the victim machine. Other The worm attempts to counteract antivirus programs by terminating the following processes: ATUPDATER.EXE AUPDATE.EXE AUTODOWN.EXE AUTOTRACE.EXE AUTOUPDATE.EXE AVLTMAIN.EXE AVPUPD.EXE AVWUPD32.EXE AVXQUAR.EXE CFIAUDIT.EXE DRWEBUPW.EXE ICSSUPPNT.EXE ICSUPP95.EXE LUALL.EXE MCUPDATE.EXE NUPGRADE.EXE OUTPOST.EXE UPDATE.EXE The worm is programmed to cease propagation after 25th March 2004.
Check other viruses! Be aware! Use Antiviral Software
Sql.953
Description Sql.953
It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. It contains the text string: SqL.
Squad.1299
Description Squad.1299
It is a very dangerous memory resident encrypted parasitic virus. It hooks INT 10h, 17h, 21h and writes itself to the end of COM and EXE files that are executed. On opening .C, .CPP, .PAS, .TXT and .PRG files the virus overwrites them with the text: This virus is a publicity stunt of the DOG SQUAD (CSE 93 Batch of RECJ) and has been issued in public interest by the Registar of the Squad. Long Live N.P.
The virus disables printing (INT 17h) and several graphic video modes (INT 10h).
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|