|
This morning I received an email through info-tech from hadams with the “RE:” as the subject. It looks to be a virus, because it had and attachment of “Price.cpl” and the message of ” :)) “ While looking into this I found that W32/Bagle-AZ virus uses the Subject “RE:” and the text message of” :))” Unfortunately, most of you opened that email before you will open this one. Thanks to Rex for bringing this to my attention. I have pasted the info for this virus below and have given a URL of more info on the virus on Sophos website.
http://www.sophos.com/virusinfo/analyses/w32bagleaz.html ------------------------------------------------------------------------------------------------------------------------
W32/Bagle-AZ is a worm which spreads using email and shared folders. The worm forges the sender address of the email. Emails sent by the worm have the following characteristics: Subject
lines: Message
texts: Attached
file: The worm harvests email addresses from the files found on the hard disk. When run the worm will create copies of itself named bawindo.exe, bawindo.exeopen and bawindo.exeopenopen in the Windows system folder. The worm adds the registry entry HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ W32/Bagle-AZ copies itself to any folder with the string 'shar' in its name using the following filenames: ACDSee
9.exe W32/Bagle-AZ deletes the following entries from the registry under HKLM\Software\Microsoft\Windows\CurrentVersion\Run
and Sophos anti-virus products since version 3.86 have been capable of detecting this worm as W32/Bagle-Gen without requiring an update.
Jason Kehoe
|
