This morning I received an email through info-tech from hadams with the “RE:” as the subject. It looks to be a virus, because it had and attachment of “Price.cpl” and the message of ” :)) “

While looking into this I found that W32/Bagle-AZ virus uses the Subject “RE:” and the text message of” :))” Unfortunately, most of you opened that email before you will open this one. Thanks to Rex for bringing this to my attention.

I have pasted the info for this virus below and have given a URL of more info on the virus on Sophos website.

 

 

http://www.sophos.com/virusinfo/analyses/w32bagleaz.html

------------------------------------------------------------------------------------------------------------------------

 

W32/Bagle-AZ is a worm which spreads using email and shared folders. The worm forges the sender address of the email.

Emails sent by the worm have the following characteristics:

Subject lines:
Re: Hello
Re: Hi
Re:
Re: Thank you!
Re: Thanks :)

Message texts:
:)
:))

Attached file:
price.cpl
joke.cpl

The worm harvests email addresses from the files found on the hard disk.

When run the worm will create copies of itself named bawindo.exe, bawindo.exeopen and bawindo.exeopenopen in the Windows system folder.

The worm adds the registry entry

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
bawindo = %SYSTEM%\bawindo.exe

W32/Bagle-AZ copies itself to any folder with the string 'shar' in its name using the following filenames:

ACDSee 9.exe
Adobe Photoshop 9 full.exe
Ahead Nero 7.exe
KAV 5.0
Kaspersky Antivirus 5.0
Matrix 3 Revolution English Subtitles.exe
Microsoft Office 2003 Crack, Working!.exe
Microsoft Office XP working Crack, Keygen.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Opera 8 New!.exe
Porno Screensaver.scr
Porno pics arhive, xxx.exe
Porno, sex, oral, anal cool, awesome!!.exe
Serials.txt.exe
WinAmp 5 Pro Keygen Crack Update.exe
WinAmp 6 New!.exe
Windown Longhorn Beta Leak.exe
Windows Sourcecode update.doc.exe
XXX hardcore images.exe

W32/Bagle-AZ deletes the following entries from the registry under

HKLM\Software\Microsoft\Windows\CurrentVersion\Run and
HKCU\Software\Microsoft\Windows\CurrentVersion\Run :
My AV
Zone Labs Client Ex
9XHtProtect
Antivirus
Special Firewall Service
service
Tiny AV
ICQNet
HtProtect
NetDy
Jammer2nd
FirewallSvr
MsInfo
SysMonXP
EasyAV
PandaAVEngine
Norton Antivirus AV
KasperskyAVEng
SkynetsRevenge
ICQ Net

Sophos anti-virus products since version 3.86 have been capable of detecting this worm as W32/Bagle-Gen without requiring an update.

 

Jason Kehoe
Network Engineer
Prairie Lakes AEA 8
(515) 574-5477
(800) 669-2325 x5477
[EMAIL PROTECTED]

 

Reply via email to