Prevent Online Threats

I-Worm.Bagle

Details
I-Worm.Bagle.y

This worm spreads via the Internet as an attachment to infected messages. The worm itself is a PE EXE file of approximately 38KB, packed using UPX. The unpacked file is approximately 70KB in size.
Characteristics of infected messages
Sender’s address (chosen at random from the following):
annie
ann
christina
christy
jessie
lizie
secretGurl
Message header (chosen at random from the following):
Encrypted document
Fax Message Received
Forum notify
Hello!
Hey!
Hidden message
I just need a friend
I like you
I’m a sad girlall
I’m bored with this life
Incoming message
Let’s socialize, my friend!
Let’s talk, my friend!
Notify from a known person ;-)
Protected message
Re: Document
Re: Hello
Re: Hi
Re: Incoming Fax
Re: Incoming Message
Re: Msg reply
RE: Protected message
RE: Text message
Re: Thank you!
Re: Thanks :)
Re: Yahoo!
Request response
Site changes
Message body:
There is a wide range of possible message texts.
The message may contain a VBS script; if this is launched by the user, it exploits a Microsoft Internet Explorer vulnerability (defined in Microsoft Security Bulletin MS03-040) which makes it possible to download the executable worm file via the Internet from several dozen infected web sites.
Attachment name:
Random, with one of the following extensions: .exe .com .scr .cpl. hta .vbs .zip
Installation
Once launched, the worm copies itself to the Windows system directory under the name “drvsys.exe”, and registers this file in the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“drvsys.exe” = “%system%\drvsys.exe”
and creates the following files in the Windows system directory
drvsys.exeopen
drvsys.exeopenopen
When starting, the worm displays the message shown below:

The worm searches the system register for keys created by other worms (e.g. Netsky) and deletes them:
9XHtProtect
Antivirus
EasyAV
FirewallSvr
HtProtect
ICQ Net
ICQNet
Jammer2nd
KasperskyAVEng
MsInfo
My AV
NetDy
Norton Antivirus AV
PandaAVEngine
service
Special Firewall Service
SysMonXP
Tiny AV
Zone Labs Client Ex
The worm also attempts to connect to a range of remote sites, and to save information about the victim computer on these sites.
Propagation
The worm searches the computer for files with the following extensions:
adb
asp
cfg
cgi
dbx
dhtm
eml
htm
jsp
mdx
mbx
mht
mmf
msg
nch
ods
oft
php
pl
sht
shtm
stm
tbb
txt
uin
wab
wsh
xls
xml

and sends itself to all email addresses found in these files.
It uses its own SMTP-server to send messages.
Propagation via P2P
The worm searches the computer for folders where the name contains the word ’shar’ and copies itself several times to each folder found, under the following names:
ACDSee 9.exe
Adobe Photoshop 9 full.exe
Ahead Nero 7.exe
Kaspersky Antivirus 5.0
KAV 5.0
Matrix 3 Revolution English Subtitles.exe
Microsoft Office 2003 Crack, Working!.exe
Microsoft Office XP working Crack, Keygen.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Opera 8 New!.exe
Porno pics arhive, xxx.exe
Porno Screensaver.scr
Porno, sex, oral, anal cool, awesome!!.exe
Serials.txt.exe
WinAmp 5 Pro Keygen Crack Update.exe
WinAmp 6 New!.exe
Windown Longhorn Beta Leak.exe
Windows Sourcecode update.doc.exe
XXX hardcore images.exe
Remote administration
The worm opens port 2535 and tracks port activity. The backdoor function makes it possible to remotely execute commands and download files to the victim machine.
Other
The worm attempts to combat antivirus programs and firewalls by terminating the following memory processes:
AGENTSVR.EXE
ANTI-TROJAN.EXE
ANTIVIRUS.EXE
ANTS.EXE
APIMONITOR.EXE
APLICA32.EXE
APVXDWIN.EXE
ATCON.EXE
ATGUARD.EXE
ATRO55EN.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVCONSOL.EXE
AVGSERV9.EXE
AVLTMAIN.EXE
AVprotect9x.exe
AVPUPD.EXE
AVSYNMGR.EXE
AVWUPD32.EXE
AVXQUAR.EXE
BD_PROFESSIONAL.EXE
BIDEF.EXE
BIDSERVER.EXE
BIPCP.EXE
BIPCPEVALSETUP.EXE
BISP.EXE
BLACKD.EXE
BLACKICE.EXE
BOOTWARN.EXE
BORG2.EXE
BS120.EXE
CDP.EXE
CFGWIZ.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFINET.EXE
CFINET32.EXE
CLEAN.EXE
CLEANER.EXE
CLEANER3.EXE
CLEANPC.EXE
CMGRDIAN.EXE
CMON016.EXE
CPD.EXE
CPF9X206.EXE
CPFNT206.EXE
CV.EXE
CWNB181.EXE
CWNTDWMO.EXE
DEFWATCH.EXE
DEPUTY.EXE
DPF.EXE
DPFSETUP.EXE
DRWATSON.EXE
DRWEBUPW.EXE
ENT.EXE
ESCANH95.EXE
ESCANHNT.EXE
ESCANV95.EXE
EXANTIVIRUS-CNET.EXE
FAST.EXE
FIREWALL.EXE
FLOWPROTECTOR.EXE
FP-WIN_TRIAL.EXE
FRW.EXE
FSAV.EXE
FSAV530STBYB.EXE
FSAV530WTBYB.EXE
FSAV95.EXE
GBMENU.EXE
GBPOLL.EXE
GUARD.EXE
GUARDDOG.EXE
HACKTRACERSETUP.EXE
HTLOG.EXE
HWPE.EXE
IAMAPP.EXE
IAMSERV.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFW2000.EXE
IPARMOR.EXE
IRIS.EXE
JAMMER.EXE
KAVLITE40ENG.EXE
KAVPERS40ENG.EXE
KERIO-PF-213-EN-WIN.EXE
KERIO-WRL-421-EN-WIN.EXE
KERIO-WRP-421-EN-WIN.EXE
KILLPROCESSSETUP161.EXE
LDPRO.EXE
LOCALNET.EXE
LOCKDOWN.EXE
LOCKDOWN2000.EXE
LSETUP.EXE
LUALL.EXE
LUCOMSERVER.EXE
LUINIT.EXE
MCAGENT.EXE
MCUPDATE.EXE
MFW2EN.EXE
MFWENG3.02D30.EXE
MGUI.EXE
MINILOG.EXE
MOOLIVE.EXE
MRFLUX.EXE
MSCONFIG.EXE
MSINFO32.EXE
MSSMMC32.EXE
MU0311AD.EXE
NAV80TRY.EXE
NAVAPW32.EXE
NAVDX.EXE
NAVSTUB.EXE
NAVW32.EXE
NC2000.EXE
NCINST4.EXE
NDD32.EXE
NEOMONITOR.EXE
NETARMOR.EXE
NETINFO.EXE
NETMON.EXE
NETSCANPRO.EXE
NETSPYHUNTER-1.2.EXE
NETSTAT.EXE
NISSERV.EXE
NISUM.EXE
NMAIN.EXE
NORTON_INTERNET_SECU_3.0_407.EXE
NPF40_TW_98_NT_ME_2K.EXE
NPFMESSENGER.EXE
NPROTECT.EXE
NSCHED32.EXE
NTVDM.EXE
NUPGRADE.EXE
NVARCH16.EXE
NWINST4.EXE
NWTOOL16.EXE
OSTRONET.EXE
OUTPOST.EXE
OUTPOSTINSTALL.EXE
OUTPOSTPROINSTALL.EXE
PADMIN.EXE
PANIXK.EXE
PAVPROXY.EXE
PCC2002S902.EXE
PCC2K_76_1436.EXE
PCCIOMON.EXE
PCDSETUP.EXE
PCFWALLICON.EXE
PCIP10117_0.EXE
PDSETUP.EXE
PERISCOPE.EXE
PERSFW.EXE
PF2.EXE
PFWADMIN.EXE
PINGSCAN.EXE
PLATIN.EXE
POPROXY.EXE
POPSCAN.EXE
PORTDETECTIVE.EXE
PPINUPDT.EXE
PPTBC.EXE
PPVSTOP.EXE
PROCEXPLORERV1.0.EXE
PROPORT.EXE
PROTECTX.EXE
PSPF.EXE
PURGE.EXE
PVIEW95.EXE
QCONSOLE.EXE
QSERVER.EXE
RAV8WIN32ENG.EXE
REGEDIT.EXE
REGEDT32.EXE
RESCUE.EXE
RESCUE32.EXE
RRGUARD.EXE
RSHELL.EXE
RTVSCN95.EXE
RULAUNCH.EXE
SAFEWEB.EXE
SBSERV.EXE
SD.EXE
SETUP_FLOWPROTECTOR_US.EXE
SETUPVAMEEVAL.EXE
SFC.EXE
SGSSFW32.EXE
SH.EXE
SHELLSPYINSTALL.EXE
SHN.EXE
SMC.EXE
SOFI.EXE
SPF.EXE
SPHINX.EXE
SPYXX.EXE
SS3EDIT.EXE
ST2.EXE
SUPFTRL.EXE
SUPPORTER5.EXE
SYMPROXYSVC.EXE
SYSEDIT.EXE
TASKMON.EXE
TAUMON.EXE
TAUSCAN.EXE
TC.EXE
TCA.EXE
TCM.EXE
TDS2-98.EXE
TDS2-NT.EXE
TDS-3.EXE
TFAK5.EXE
TGBOB.EXE
TITANIN.EXE
TITANINXP.EXE
TRACERT.EXE
TRJSCAN.EXE
TRJSETUP.EXE
TROJANTRAP3.EXE
UNDOBOOT.EXE
UPDATE.EXE
VBCMSERV.EXE
VBCONS.EXE
VBUST.EXE
VBWIN9X.EXE
VBWINNTW.EXE
VCSETUP.EXE
VFSETUP.EXE
VIRUSMDPERSONALFIREWALL.EXE
VNLAN300.EXE
VNPC3000.EXE
VPC42.EXE
VPFW30S.EXE
VPTRAY.EXE
VSCENU6.02D30.EXE
VSECOMR.EXE
VSHWIN32.EXE
VSISETUP.EXE
VSMAIN.EXE
VSMON.EXE
VSSTAT.EXE
VSWIN9XE.EXE
VSWINNTSE.EXE
VSWINPERSE.EXE
W32DSM89.EXE
W9X.EXE
WATCHDOG.EXE
WEBSCANX.EXE
WGFE95.EXE
WHOSWATCHINGME.EXE
WINRECON.EXE
WNT.EXE
WRADMIN.EXE
WRCTRL.EXE
WSBGATE.EXE
WYVERNWORKSFIREWALL.EXE
XPF202EN.EXE
ZAPRO.EXE
ZAPSETUP3001.EXE
ZATUTOR.EXE
ZAUINST.EXE
ZONALM2601.EXE
ZONEALARM.EXE

Related Posts

  • Email-Worm.Win32.Bagle.d
  • Email-Worm.Win32.Bagle.e
  • I-Worm.Bagle.a
  • Email-Worm.Win32.Bagle.c
  • Email-Worm.Win32.Bagle.c
  • Leave a Reply

    I-Worm.Bagle

    Details
    I-Worm.Bagle.t

    This new member of the Bagle family closely resembles it’s predecessor, Bagle.s. Infected emails also have empty subjects and message bodies. In Bagle.t the attachment is 8208 bytes in size. Bagle.t is compressed by FSG and the unpacked file is about 37KB in size.
    This e-mail worm is relatively simple compared to most of the other members in the Bagle family, leading to the suspicion it may have been written by a different group, with access to the Bagle sources.
    Infected messages have the following characteristics:
    Sender address:
    random
    Subject:
    none
    Body:
    empty
    Attachment name:
    game
    Attachment file type:
    .exe
    Installation
    When executed, Bage.t copies itself in to the Windows system directory under the name “sysinfo.exe” and register itself to be run during system startup. It will also create a registry key named:
    [HKEY_CURRENT_USER\SOFTWARE\Windows2005]
    and register a backdoor on port 4751, which can be used to install new malware in the system.
    Propagation
    Just like Bagle.s, this variant will not spread if the system date is any year later than 2004.
    During all of 2004 Bagle.t will begin to extract e-mail addresses from various files from the disk and start mailing itself to these. Targeted file extensions are: .wab .txt .msg .htm .shtm .stm .xml .dbx .mbx .mdx .eml .nch .mmf .ods .cfg .asp .php .wsh .adb .tbb .sht .xls .oft .uin .cgi .mht .dhtm .jsp.
    While spreading, infected e-mails will not be sent to addresses containing ‘@avp.’ and ‘@microsoft’.
    Other
    Bagle.t tries to report infections by accessing a URL on the site “www.werde.de” with some specific parameters which the virus-writer supposedly can later query. At the time of writing, the URL seems to have been taken down.
    To mask the system infection under an apparent useful action, the worm will attempt to execute a file named dreder.exe, which doesn’t exist by default in standard Windows installations.

    Related Posts

  • Email-Worm.Win32.Bagle.d
  • Email-Worm.Win32.Bagle.e
  • I-Worm.Bagle.a
  • Email-Worm.Win32.Bagle.c
  • Email-Worm.Win32.Bagle.c
  • Leave a Reply

    I-Worm.Bagle

    Details
    I-Worm.Bagle.z

    Bagle.z is an Internet worm spreading as an infected email attachment. The worm is a PE EXE file about 20-22 KB. Bagle.z is packed with UPX and the unpacked file size is 55 KB.
    The body of the worm contains a new poem:
    In a difficult world
    In a nameless time
    I want to survive
    So, you will be mine
    — Bagle Author, 29.04.04, Germany.
    Infected message characteristics
    Sender address:
    random
    Subject:
    Re: Msg reply
    Re: Hello
    Re: Yahoo!
    Re: Thank you!
    Re: Thanks :)
    RE: Text message
    Re: Document
    Incoming message
    Re: Incoming Message
    RE: Incoming Msg
    RE: Message Notify
    Notification
    Changes..
    New changes
    Hidden message
    Fax Message Received
    Protected message
    RE: Protected message
    Forum notify
    Site changes
    Re: Hi
    Encrypted document
    Attachment name:
    Information
    Details
    text_document
    Readme
    Document
    Info
    the_message
    Details
    MoreInfo
    Message
    You_will_answer_to_me
    Half_Live
    Counter_strike
    Loves_money
    the_message
    Alive_condom
    Joke
    Toy
    Nervous_illnesses
    Manufacture
    You_are_dismissed
    Your_complaint
    Your_money
    Smoke
    I_search_for_you
    Attachment characteristics:
    .exe .com .scr and .cpl binary code file
    .vbs script
    .hta html-file
    ZIP zrchive represented by a thumbnail. This archive contains two files with random names. The .exe file contains the body of the worm, while the second one contains random characters and has different extensions: .sys, .dat, .idx, .vxd, .vid or .dll.
    Message body
    There is a wide range of possible message texts.
    The message may contain a VBS script; if this is launched by the user, it exploits a Microsoft Internet Explorer vulnerability (defined in Microsoft Security Bulletin MS03-040) which makes it possible to download the executable worm file via the Internet from several dozen infected web sites.
    Installation
    Upon first being launched the worm displays a fake error message:

    and then copies itself to the Windows system directory under the name “drvsys.exe”, and registers this file in the system registry autorun key:
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    “drvddll.exe” = “%system%\drvddll.exe”
    Bagle.z also creates the following files in the Windows system directory:
    drvddll.exeopen
    drvddll.exeopenopen
    It searches for and deletes the following keys:
    My AV
    Zone Labs Client Ex
    9XHtProtect
    Antivirus
    Special Firewall Service
    service
    Tiny AV
    ICQNet
    HtProtect
    NetDy
    Jammer2nd
    FirewallSvr
    MsInfo
    SysMonXP
    EasyAV
    PandaAVEngine
    Norton Antivirus AV
    KasperskyAVEng
    SkynetsRevenge
    ICQ Net
    The worm also attempts to connect to a range of remote sites, and to save information about the victim computer on these sites.
    Propagation
    The worm searches the computer for files with the following extensions:
    adb
    asp
    cfg
    cgi
    dbx
    dhtm
    eml
    htm
    jsp
    mdx
    mbx
    mht
    mmf
    msg
    nch
    ods
    oft
    php
    pl
    sht
    shtm
    stm
    tbb
    txt
    uin
    wab
    wsh
    xls
    xml

    and sends itself to all email addresses found in these files.
    Bagle.z does not send copies to addresses containing the text strings below:
    @microsoft
    rating@
    f-secur
    news
    update
    anyone@
    bugs@
    contract@
    feste
    gold-
    certs@
    help@
    info@
    nobody@
    noone@
    kasp
    admin
    icrosoft
    support
    ntivi
    unix
    bsd
    lin
    ux
    listserv
    certific
    sopho
    @foo
    @iana
    free-av
    @messagelab
    winzip
    google
    winrar
    samples
    abuse
    panda
    cafee
    spam
    pgp
    @avp.
    noreply
    local root@
    postmaster@
    It uses its own SMTP-server to send messages.
    Propagation via P2P
    The worm searches the computer for folders where the name contains the word ’shar’ and copies itself several times to each folder found, under the following names:
    ACDSee 9.exe
    Adobe Photoshop 9 full.exe
    Ahead Nero 7.exe
    Kaspersky Antivirus 5.0
    KAV 5.0
    Matrix 3 Revolution English Subtitles.exe
    Microsoft Office 2003 Crack, Working!.exe
    Microsoft Office XP working Crack, Keygen.exe
    Microsoft Windows XP, WinXP Crack, working Keygen.exe
    Opera 8 New!.exe
    Porno pics arhive, xxx.exe
    Porno Screensaver.scr
    Porno, sex, oral, anal cool, awesome!!.exe
    Serials.txt.exe
    WinAmp 5 Pro Keygen Crack Update.exe
    WinAmp 6 New!.exe
    Windown Longhorn Beta Leak.exe
    Windows Sourcecode update.doc.exe
    XXX hardcore images.exe
    Remote administration
    Remote administration
    The worm opens port 2535 and tracks port activity. The backdoor function makes it possible to remotely execute commands and download files to the victim machine.
    Other
    The worm attempts to combat antivirus programs and firewalls by terminating the following memory processes:
    AGENTSVR.EXE
    ANTI-TROJAN.EXE
    ANTIVIRUS.EXE
    ANTS.EXE
    APIMONITOR.EXE
    APLICA32.EXE
    APVXDWIN.EXE
    ATCON.EXE
    ATGUARD.EXE
    ATRO55EN.EXE
    ATUPDATER.EXE
    ATWATCH.EXE
    AUPDATE.EXE
    AUTODOWN.EXE
    AUTOTRACE.EXE
    AUTOUPDATE.EXE
    AVCONSOL.EXE
    AVGSERV9.EXE
    AVLTMAIN.EXE
    AVprotect9x.exe
    AVPUPD.EXE
    AVSYNMGR.EXE
    AVWUPD32.EXE
    AVXQUAR.EXE
    BD_PROFESSIONAL.EXE
    BIDEF.EXE
    BIDSERVER.EXE
    BIPCP.EXE
    BIPCPEVALSETUP.EXE
    BISP.EXE
    BLACKD.EXE
    BLACKICE.EXE
    BOOTWARN.EXE
    BORG2.EXE
    BS120.EXE
    CDP.EXE
    CFGWIZ.EXE
    CFIADMIN.EXE
    CFIAUDIT.EXE
    CFINET.EXE
    CFINET32.EXE
    CLEAN.EXE
    CLEANER.EXE
    CLEANER3.EXE
    CLEANPC.EXE
    CMGRDIAN.EXE
    CMON016.EXE
    CPD.EXE
    CPF9X206.EXE
    CPFNT206.EXE
    CV.EXE
    CWNB181.EXE
    CWNTDWMO.EXE
    DEFWATCH.EXE
    DEPUTY.EXE
    DPF.EXE
    DPFSETUP.EXE
    DRWATSON.EXE
    DRWEBUPW.EXE
    ENT.EXE
    ESCANH95.EXE
    ESCANHNT.EXE
    ESCANV95.EXE
    EXANTIVIRUS-CNET.EXE
    FAST.EXE
    FIREWALL.EXE
    FLOWPROTECTOR.EXE
    FP-WIN_TRIAL.EXE
    FRW.EXE
    FSAV.EXE
    FSAV530STBYB.EXE
    FSAV530WTBYB.EXE
    FSAV95.EXE
    GBMENU.EXE
    GBPOLL.EXE
    GUARD.EXE
    GUARDDOG.EXE
    HACKTRACERSETUP.EXE
    HTLOG.EXE
    HWPE.EXE
    IAMAPP.EXE
    IAMSERV.EXE
    ICLOAD95.EXE
    ICLOADNT.EXE
    ICMON.EXE
    ICSSUPPNT.EXE
    ICSUPP95.EXE
    ICSUPPNT.EXE
    IFW2000.EXE
    IPARMOR.EXE
    IRIS.EXE
    JAMMER.EXE
    KAVLITE40ENG.EXE
    KAVPERS40ENG.EXE
    KERIO-PF-213-EN-WIN.EXE
    KERIO-WRL-421-EN-WIN.EXE
    KERIO-WRP-421-EN-WIN.EXE
    KILLPROCESSSETUP161.EXE
    LDPRO.EXE
    LOCALNET.EXE
    LOCKDOWN.EXE
    LOCKDOWN2000.EXE
    LSETUP.EXE
    LUALL.EXE
    LUCOMSERVER.EXE
    LUINIT.EXE
    MCAGENT.EXE
    MCUPDATE.EXE
    MFW2EN.EXE
    MFWENG3.02D30.EXE
    MGUI.EXE
    MINILOG.EXE
    MOOLIVE.EXE
    MRFLUX.EXE
    MSCONFIG.EXE
    MSINFO32.EXE
    MSSMMC32.EXE
    MU0311AD.EXE
    NAV80TRY.EXE
    NAVAPW32.EXE
    NAVDX.EXE
    NAVSTUB.EXE
    NAVW32.EXE
    NC2000.EXE
    NCINST4.EXE
    NDD32.EXE
    NEOMONITOR.EXE
    NETARMOR.EXE
    NETINFO.EXE
    NETMON.EXE
    NETSCANPRO.EXE
    NETSPYHUNTER-1.2.EXE
    NETSTAT.EXE
    NISSERV.EXE
    NISUM.EXE
    NMAIN.EXE
    NORTON_INTERNET_SECU_3.0_407.EXE
    NPF40_TW_98_NT_ME_2K.EXE
    NPFMESSENGER.EXE
    NPROTECT.EXE
    NSCHED32.EXE
    NTVDM.EXE
    NUPGRADE.EXE
    NVARCH16.EXE
    NWINST4.EXE
    NWTOOL16.EXE
    OSTRONET.EXE
    OUTPOST.EXE
    OUTPOSTINSTALL.EXE
    OUTPOSTPROINSTALL.EXE
    PADMIN.EXE
    PANIXK.EXE
    PAVPROXY.EXE
    PCC2002S902.EXE
    PCC2K_76_1436.EXE
    PCCIOMON.EXE
    PCDSETUP.EXE
    PCFWALLICON.EXE
    PCIP10117_0.EXE
    PDSETUP.EXE
    PERISCOPE.EXE
    PERSFW.EXE
    PF2.EXE
    PFWADMIN.EXE
    PINGSCAN.EXE
    PLATIN.EXE
    POPROXY.EXE
    POPSCAN.EXE
    PORTDETECTIVE.EXE
    PPINUPDT.EXE
    PPTBC.EXE
    PPVSTOP.EXE
    PROCEXPLORERV1.0.EXE
    PROPORT.EXE
    PROTECTX.EXE
    PSPF.EXE
    PURGE.EXE
    PVIEW95.EXE
    QCONSOLE.EXE
    QSERVER.EXE
    RAV8WIN32ENG.EXE
    REGEDIT.EXE
    REGEDT32.EXE
    RESCUE.EXE
    RESCUE32.EXE
    RRGUARD.EXE
    RSHELL.EXE
    RTVSCN95.EXE
    RULAUNCH.EXE
    SAFEWEB.EXE
    SBSERV.EXE
    SD.EXE
    SETUP_FLOWPROTECTOR_US.EXE
    SETUPVAMEEVAL.EXE
    SFC.EXE
    SGSSFW32.EXE
    SH.EXE
    SHELLSPYINSTALL.EXE
    SHN.EXE
    SMC.EXE
    SOFI.EXE
    SPF.EXE
    SPHINX.EXE
    SPYXX.EXE
    SS3EDIT.EXE
    ST2.EXE
    SUPFTRL.EXE
    SUPPORTER5.EXE
    SYMPROXYSVC.EXE
    SYSEDIT.EXE
    TASKMON.EXE
    TAUMON.EXE
    TAUSCAN.EXE
    TC.EXE
    TCA.EXE
    TCM.EXE
    TDS2-98.EXE
    TDS2-NT.EXE
    TDS-3.EXE
    TFAK5.EXE
    TGBOB.EXE
    TITANIN.EXE
    TITANINXP.EXE
    TRACERT.EXE
    TRJSCAN.EXE
    TRJSETUP.EXE
    TROJANTRAP3.EXE
    UNDOBOOT.EXE
    UPDATE.EXE
    VBCMSERV.EXE
    VBCONS.EXE
    VBUST.EXE
    VBWIN9X.EXE
    VBWINNTW.EXE
    VCSETUP.EXE
    VFSETUP.EXE
    VIRUSMDPERSONALFIREWALL.EXE
    VNLAN300.EXE
    VNPC3000.EXE
    VPC42.EXE
    VPFW30S.EXE
    VPTRAY.EXE
    VSCENU6.02D30.EXE
    VSECOMR.EXE
    VSHWIN32.EXE
    VSISETUP.EXE
    VSMAIN.EXE
    VSMON.EXE
    VSSTAT.EXE
    VSWIN9XE.EXE
    VSWINNTSE.EXE
    VSWINPERSE.EXE
    W32DSM89.EXE
    W9X.EXE
    WATCHDOG.EXE
    WEBSCANX.EXE
    WGFE95.EXE
    WHOSWATCHINGME.EXE
    WINRECON.EXE
    WNT.EXE
    WRADMIN.EXE
    WRCTRL.EXE
    WSBGATE.EXE
    WYVERNWORKSFIREWALL.EXE
    XPF202EN.EXE
    ZAPRO.EXE
    ZAPSETUP3001.EXE
    ZATUTOR.EXE
    ZAUINST.EXE
    ZONALM2601.EXE
    ZONEALARM.EXE

    Related Posts

  • Email-Worm.Win32.Bagle.d
  • Email-Worm.Win32.Bagle.e
  • I-Worm.Bagle.a
  • Email-Worm.Win32.Bagle.c
  • Email-Worm.Win32.Bagle.c
  • Leave a Reply

    I-Worm.Bagle

    Details
    I-Worm.Bagle.s
    Bagle.s is an Internet worm spreading as an attachment to infected emails.
    The worm is a PE exe file about 8 KB in size. Bagle.s is compressed by FSG and the unpacked file is about 37KB in size.
    Infected messages have the following characteristics:
    Sender address:
    random
    Subject:
    none
    Body:
    empty
    Attachment name:
    random characters
    Attachment file type:
    .exe
    Installation
    After launch Bagle.s copies itself into the Windows system registry as gigabit.exe and registers this file in the system registry autorun key:
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    “gigabit.exe” = “%system%\gigabit.exe”
    Bagle.s then creates the key:
    [SOFTWARE\Windows2004]
    “gsed”
    where it stores it’s variables.
    Bagle.s also launches mshearts.exe - The Miscrosoft Hearts Network.

    Finally, Bagle.s attempts to connect to several remote sites and store id information from the infected machine on these sites.
    Propagation
    Bagle.s searches disks for files with the following extensions:
    adb
    asp
    cfg
    cgi
    dbx
    dhtm
    eml
    htm
    jsp
    mbx
    mdx
    mht
    mmf
    msg
    nch
    ods
    oft
    php
    pl
    sht
    shtm
    stm
    tbb
    txt
    uin
    wab
    wsh
    xls
    xml

    and sends copies of itself to all email addresses detected in these files using an inbuilt SMTP-engine.
    Remote Administration
    Bagle.s opens and monitors port 4751. The inbuilt backdoor function allows the master to:
    Execute commands
    Download files

    Related Posts

  • Email-Worm.Win32.Bagle.d
  • Email-Worm.Win32.Bagle.e
  • I-Worm.Bagle.a
  • Email-Worm.Win32.Bagle.c
  • Email-Worm.Win32.Bagle.c
  • Leave a Reply

    I-Worm.Bagle

    Details
    I-Worm.Bagle.j
    This worm spreads via the Internet as an attachment to infected messages, and also via file sharing networks. It is packed using UPX; the size of the compressed file is 12843 bytes, and the size of the uncompressed file is 49707 bytes. The worm may write nonsense to the end of the file, in which case the size of the file will differ from the size shown above.
    This current version is almost identical to I-Worm.Bagle.i, and differs only in the following insignificant ways:
    The text of the message sent to the author of NetSky has been changed:
    “Hey, NetSky, fuck off you bitch!”
    The name of the file which the worm writes itself has been changed, and correspondingly, so has the value of the system registry key:
    File name:
    winsys.exe
    Registry key:
    [HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Run]
    “ssate.exe” = “%system%\winsys.exe”

    Related Posts

  • Email-Worm.Win32.Bagle.d
  • Email-Worm.Win32.Bagle.e
  • I-Worm.Bagle.a
  • Email-Worm.Win32.Bagle.c
  • Email-Worm.Win32.Bagle.c
  • Leave a Reply

    I-Worm.Bagle

    Details
    I-Worm.Bagle.i
    Bagle.i is 12288 bytes in size, packed using UPX. The unpacked file is 49152 bytes in size.
    Like previous versions of Bagle, Bagle.i sometimes sends copies of itself in password protected ZIP format. In this case, the password is included in the body of the message. The zipped file is about 12KB in size.
    Infected messages have the following characteristics:
    Message header (chosen from the list below):
    E-mail account disabling warning.
    E-mail account security warning.
    Email account utilization warning.
    Important notify about your e-mail account.
    Notify about using the e-mail account.
    Notify about your e-mail account utilization.
    Warning about your e-mail account.
    Salutation (chosen from the list below):
    Dear user of “” mailing system,
    Dear user of gateway e-mail server,
    Dear user of ,
    Dear user of e-mail server ““,
    Dear user, the management of mailing system wants to let you know that,
    Hello user of e-mail server,
    Message body (chosen from the list below)
    Our antivirus software has detected a large ammount of viruses outgoing from your email account, you may use our free anti-virus tool to clean up your computer software.
    Our main mailing server will be temporary unavaible for next two days, to continue receiving mail in these days you have to configure our free auto-forwarding service.
    Some of our clients complained about the spam (negative e-mail content) outgoing from your e-mail account. Probably, you have been infected by a proxy-relay trojan server. In order to keep your computer safe, follow the instructions.
    We warn you about some attacks on your e-mail account. Your computer may contain viruses, in order to keep your computer and e-mail account safe, please, follow the instructions.
    Your e-mail account has been temporary disabled because of unauthorized access.
    Your e-mail account will be disabled because of improper using in next three days, if you are still wishing to use it, please, resign your account information.
    Conclusion (chosen from the list below):
    Advanced details can be found in attached file.
    For details see the attach.
    For details see the attached file.
    For further details see the attach.
    For more information see the attached file.
    Further details can be obtained from attached file.
    Pay attention on attached file.
    Please, read the attach for further details.
    If a copy of the virus is in zip format, one of the following sentences will be included at the end of the message:
    Attached file protected with the password for security reasons. Password is .
    For security reasons attached file is password protected. The password is “ “.
    For security purposes the attached file is password protected. Password is “ “.
    In order to read the attach you have to use the following password: .
    Signature:
    Best wishes,
    Cheers,
    Have a good day,
    Kind regards,
    Sincerely,
    The Management,
    followed by:
    The team http://www.
    When sending messages, the viruses places the domain name of the recipient’s mail server in the fields.
    Attachment name (chosen from the list below):
    Attach
    Document
    Info
    Information
    Message
    MoreInfo
    Readme
    TextDocument
    TextFile
    Attachment extensions (chosen from the list below):
    exe
    pif
    zip
    Installation
    Once launched, the worm copies itself to the Windows system directory under the name irun4.exe and registers this file in the system registry auto-run key:
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    “ssate.exe” = “%system%\irun4.exe
    It also creates a key in the registry:
    [HKCU\SOFTWARE\DateTime]
    “=”1″
    The worm attempts to connect to a number of remote sites and to save information about the infected computer on these sites.
    Propagation
    The worm searches for files with the following extensions:
    adb
    asp
    cfg
    cgi
    dbx
    eml
    htm
    mdx
    mmf
    msg
    nch
    ods
    php
    pl
    sht
    tbb
    txt
    uin
    wab
    xml
    harvests email addresses, and then sends itself to all addresses found. The worm uses its own SMTP server to send messages. It does not send messages to the following addresses:
    @avp.
    @hotmail.com
    @microsoft
    @msn.com
    local
    noreply
    postmaster@
    root@
    Propagation via P2P
    The worm searches for directories where the name contains the word shar and copies itself several times, to all files found, under the following names:
    ACDSee 9.exe
    Adobe Photoshop 9 full.exe
    Ahead Nero 7.exe
    Matrix 3 Revolution English Subtitles.exe
    Microsoft Office 2003 Crack, Working!.exe
    Microsoft Office XP working Crack, Keygen.exe
    Microsoft Windows XP, WinXP Crack, working Keygen.exe
    Opera 8 New!.exe
    Porno pics arhive, xxx.exe
    Porno Screensaver.scr
    Porno, sex, oral, anal cool, awesome!!.exe
    Serials.txt.exe
    WinAmp 5 Pro Keygen Crack Update.exe
    WinAmp 6 New!.exe
    Windown Longhorn Beta Leak.exe
    Windows Sourcecode update.doc.exe
    XXX hardcore images.exe
    Remote administration
    The worm opens port 2745 and tracks port activity. The backdoor function enables the remote execution of commands and the downloading of files to the victim machine.
    Other
    The worm attempts to counteract the updating of antivirus programs by terminating the following processes:
    ATUPDATER.EXE
    AUPDATE.EXE
    AUTODOWN.EXE
    AUTOTRACE.EXE
    AUTOUPDATE.EXE
    AVLTMAIN.EXE
    AVPUPD.EXE
    AVWUPD32.EXE
    AVXQUAR.EXE
    CFIAUDIT.EXE
    DRWEBUPW.EXE
    ICSSUPPNT.EXE
    ICSUPP95.EXE
    LUALL.EXE
    MCUPDATE.EXE
    NUPGRADE.EXE
    OUTPOST.EXE
    UPDATE.EXE
    The worm is programmed to cease propagation on 26th April 2005.

    Related Posts

  • Email-Worm.Win32.Bagle.d
  • Email-Worm.Win32.Bagle.e
  • I-Worm.Bagle.a
  • Email-Worm.Win32.Bagle.c
  • Email-Worm.Win32.Bagle.c
  • Leave a Reply

    I-Worm.Bagle

    Details
    I-Worm.Bagle.f
    This worm spreads via the Internet as a file attached to infected messages. It also spreads via file-sharing networks.
    The worm is a PE EXE file of approximately 21KB, packed using PEX. The unpacked file is approximately 35KB in size.
    The worm also sends copies of itself in a password protected ZIP file. In this case, the password is given in the message body.
    Infected messages have the following characteristics:
    Message header:
    ^_^ meay-meay!
    ^_^ mew-mew (-:
    Aline
    Anna
    Audra
    Bad girl
    Barbi
    beautiful
    Caitie
    caroline
    ello! =))
    Fotograf
    Gallery photos
    groom
    Hey, dude, it’s me ^_^ :P
    Hey, ya! =))
    Hi! :-)
    Hokki =)
    Jammie
    Juli
    Julie
    kate
    Katrina
    Kelley
    kleopatra
    Lisa
    Mandy
    Mary
    Mary-Anne
    My beautiful person
    My Name is Frenk
    My photoalbum
    My photos
    Myphotos
    Photoalbum
    rebecca
    Rena
    Sara
    stacy
    Tammy
    Wauall beautiful (-:
    Weah, hello! :-)
    Weeeeee! ;)))
    Message body:
    Argh, i don’t like the plaintext :)
    Fell free to chat with me I accept all ages. Don””t worry I don””t bite……..hope to hear from you soon!
    Hey people whats goin on? If there is anything you want to know about me ask me… I am pretty easygoing I won’t bite….not at first anywayz hahaa…..one thing I will say on here tho I am not into the Cyber thing so don’t even ask…..Ciao…
    Hey, guys! by the way, I have no problems with my sexual life, so it’s absolutly useless try to have icq sex or things like that. Thanks Hi! My name is Shreya and I am a goof off!!! So, If you love the outdoors, travelling, books, music, movies, laffing, teasing and/or can poke fun at yourself… please come a hollerin’!!
    I am from Taiwan but I study in Camden, New Jersey now. I like to know people from different places .
    I enjoy clean conversations but am open to conversing with women and men with little ones as well. I am very open-minded. All authorization requests will be denied if I don’t receive messages and get to know you first.
    I like to be in a company of smart, delicate, and with a good sense of humor people. I am Bulgarian, currently getting my Master’s in International Business in USA. Favorite actor: Michael Dudikoff I love camping, dirt track racing, going for walks, and I have 2 cats - HotRod and Deebo (named from the movie ‘Friday’ and he lives up to it!). Life is ever changing, never always easy…
    I love meeting new people and making new friends. I am a Mary Kay Beauty Consultant. I am married to a wonderful man. We have no children, exept for a minature schnauzer that thinks he is a child. Looking forward to meeting you.
    i love to chat to just about anyone!!
    I love to dance, read poetry, make people laugh, and hug as many people a day as i can.
    I sit with elders of a gentle race, whose world is seldom seen.Who sit and talk of days for which they wait, when all will be revealed. These are song lyrics.
    If I’m online, it problably means I’m pretty bored….so feel free to message me and say hi or whatever else comes to mind at the moment.
    If you are going to make me cry, at least be there to wipe away the tears *Right now the worst thing for you to tell me that I can find someone better than you, especially when you are all I want I’m a social butterfly and a natural flirt. Very hard to get my complete attention. Very open and will answer almost anything. But please don’t piss me off. I can be sweet and cuddly or a whatever mood I am in that day so everyday I’m an open minded person and enjoy chatting w/ other people. I’m free and willing to chat about anything. So feel free to Imed me if you wanna chat.
    I’m married and I stay at home. And I don’t do cyber sex so leave me the fuck alone i’m tall and skiny I’m studying in Pharm. D program in FL. i like music, movie, dancing, sports, SCUBA diving, traveling and make a lot friends.
    Looking forward for a response :P
    Love the outdoors, literature, writing, and athletics My hobbies include crochet, sewing, painting lead figures and playing AD&D. Favorite activities include fishing and camping. I love cats, unicorns(go figure), and fantasy in general.
    Nice friends, nice men, nice sex and feeling great. I don’t mind the odd bout of cybersex as I love to use my imagination when I masterbate.
    Single Mom of 3, Full time college student, Graduate in December with an Associates of Applied Science in Computer Information Systems Love the internet.
    When The Trust is Gone So Is The Love That Fades Like the Rain Washing Away All The Sorrows Of Yesterday Why I Ask Myself Must It End Like This Tomorrow, I Tell Myself, I’ll Be Okay For Now, I’ll Just Live In The Memories Of Our Life Together You don’t know what you’ve got till it’s gone *You hurt me more than I deserve, how can you be so cruel? I love you more than you deserve, how can I be such a fool?
    Attachment name
    Aline
    Anna
    Audra
    Bad girl
    Barbi
    Caitie
    caroline
    Gallery
    It_I
    Jammie
    Juli
    Julie
    kate
    Katrina
    Kelley
    kleopatra
    Lisa
    Mandy
    Mary
    Mary-Anne
    myfotos
    Photoalbum
    Photomontage
    Picture
    rebecca
    Rena
    Sara
    stacy
    Tammy
    Attachment extension:
    exe
    scr
    zip
    If the worm is sent as a ZIP file, the following message text will be found at the end of the message:
    archive password:
    pass:
    password:
    password for archive:
    Installation
    Following installation, the worm copies itself and its components to the Windows system directory under the names “i1ru54n4.exe”, “go54o.exe”, “ii5nj4.exe”, “i1ru54n4.exe” open and registers “i1ru54n4.exe” in the system registry auto-run key:
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    “rate.exe” = “%system%\i1ru54n4.exe”
    It also creates the following registry key:
    [HKCU\SOFTWARE\Winword]
    “frun”=”1″
    The worm attempts to connect to several remote sites, and saves information about the infected computer on these sites. The worm also creates a mutex called imain_mutex to flag its presence in memory.
    Propagation
    The worm searches for files with the following extensions:
    adb
    asp
    cfg
    dbx
    eml
    htm
    html
    mdx
    mmf
    nch
    ods
    php
    pl
    sht
    txt
    wab
    and sends itself to all email addresses which it finds in these files. It uses its own SMTP server to send messages.
    Propogation via P2P
    The worm searches for directories which contain shar and copies itself several times to all directories found, under the following names:
    ACDSee 9.exe
    Adobe Photoshop 9 full.exe
    Ahead Nero 7.exe
    Matrix 3 Revolution English Subtitles.exe
    Microsoft Office 2003 Crack, Working!.exe
    Microsoft Office XP working Crack, Keygen.exe
    Microsoft Windows XP, WinXP Crack, working Keygen.exe
    Opera 8 New!.exe
    Porno pics arhive, xxx.exe
    Porno Screensaver.scr
    Porno, sex, oral, anal cool, awesome!!.exe
    Serials.txt.exe
    WinAmp 5 Pro Keygen Crack Update.exe
    WinAmp 6 New!.exe
    Windown Longhorn Beta Leak.exe
    Windows Sourcecode update.doc.exe
    XXX hardcore images.exe
    Remote administration
    The worm opens port 2475 and tracks port activity. The backdoor function makes it possible for commands to be executed and files to be downloaded on the victim machine.
    Other
    The worm attempts to counteract the updating of antivirus programs. It terminates the following system processes:
    ATUPDATER.EXE
    AUPDATE.EXE
    AUTODOWN.EXE
    AUTOTRACE.EXE
    AUTOUPDATE.EXE
    AVLTMAIN.EXE
    AVPUPD.EXE
    AVWUPD32.EXE
    AVXQUAR.EXE
    CFIAUDIT.EXE
    DRWEBUPW.EXE
    ICSSUPPNT.EXE
    ICSUPP95.EXE
    LUALL.EXE
    MCUPDATE.EXE
    NUPGRADE.EXE
    OUTPOST.EXE
    UPDATE.EXE
    The worm is programmed to cease propagation after 25th March 2004.

    Related Posts

  • Email-Worm.Win32.Bagle.d
  • Email-Worm.Win32.Bagle.e
  • I-Worm.Bagle.a
  • Email-Worm.Win32.Bagle.c
  • Email-Worm.Win32.Bagle.c
  • Leave a Reply

    I-Worm.Bagle

    Details
    I-Worm.Bagle.e
    This worm spreads via the Internet as a file attached to infected emails. The worm itself is a PE EXE file of approximately 17KB, packed using PEX. The unpacked file is approximately 27KB in size.
    Infected messages have the following characteristics:
    Message header (chosen from the list below):
    Accounts department
    Ahtung!
    Camila
    Daily activity report
    Ello!
    Flayers among us
    Freedom for everyone
    From Hair-cutter
    From me
    Greet the day
    Hardware devices price-list
    Hello my friend
    Hi!
    Jenny
    Jessica
    Looking for the report
    Maria
    Melissa
    Monthly incomings summary
    New Price-list
    Price
    Price list
    Pricelist
    Price-list
    Proclivity to servitude
    Registration confirmation
    The account
    The employee
    The summary
    USA government abolishes the capital punishment Weekly activity report Wellall
    You are dismissed
    You really love me? he he
    Message body (chosen from the list below):
    Cya
    Empty
    Everything inside the attach
    Look it through
    Request
    Response
    Subj
    Attachment:
    The attachment is a zip file which a name consisting of a random combination of a, b, and c (e.g. cdda.zip). Inside the .zip file is an .exe file with a random name, containing a text file icon.
    Installation
    Following installation, the worm copies itself and its components to the Windows system directory, under the names “i1ru74n4.exe”, “godo.exe”, “ii455nj4.exe”, and “i1ru74n4.exeopen”. It registers “i1ru74n4.exe” in the system registry auto-run key:
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    “rate.exe” = “%system%\i1ru74n4.exe”
    The worm also creates the registry key:
    [HKCU\SOFTWARE\DateTime4]
    and saves its variables in the key.
    The worm attempts to connect to several sites and save information about the infected victim computer on these sites.
    The worm also creates a mutex imain_mutex to flag its presence in memory.
    Propagation
    The worm searches for files with the following extentions:
    adb
    asp
    cfg
    dbx
    eml
    htm
    html
    mdx
    mmf
    nch
    ods
    php
    pl
    sht
    txt
    wab
    harvests email addresses, and then sends itself to all addresses found. To send messages, the worm uses its own SMTP server.
    Remote administration
    The worm opens port 2745 and tracks port activity. The backdoor function makes it possible to remotely execute commands and download files to the victim machine.
    Other
    The worm attempts to counteract antivirus programs by terminating the following processes:
    ATUPDATER.EXE
    AUPDATE.EXE
    AUTODOWN.EXE
    AUTOTRACE.EXE
    AUTOUPDATE.EXE
    AVLTMAIN.EXE
    AVPUPD.EXE
    AVWUPD32.EXE
    AVXQUAR.EXE
    CFIAUDIT.EXE
    DRWEBUPW.EXE
    ICSSUPPNT.EXE
    ICSUPP95.EXE
    LUALL.EXE
    MCUPDATE.EXE
    NUPGRADE.EXE
    OUTPOST.EXE
    UPDATE.EXE
    The worm is programmed to cease propagation after 25th March 2004.

    Related Posts

  • Email-Worm.Win32.Bagle.d
  • Email-Worm.Win32.Bagle.e
  • I-Worm.Bagle.a
  • Email-Worm.Win32.Bagle.c
  • Email-Worm.Win32.Bagle.c
  • Leave a Reply

    I-Worm.Bagle

    Details
    I-Worm.Bagle.d
    This worm spreads via the Internet in the form of an attachment to infected emails.
    The worm itself is a PE EXE file of approximately 15KB, compressed using UPX. The size of the decompressed file is approximately 28KB.
    Characteristics of infected messages
    Message header:
    Accounts department
    Ahtung!
    Camila
    Daily activity report
    Flayers among us
    Freedom for everyone
    From Hair-cutter
    From me
    Greet the day
    Hardware devices price-list
    Hello my friend
    Hi!
    Jenny
    Jessica
    Looking for the report
    Maria
    Melissa
    Monthly incomings summary
    New Price-list
    Price
    Price list
    Pricelist
    Price-list
    Proclivity to servitude
    Registration confirmation
    The account
    The employee
    The summary
    USA government abolishes the capital punishment
    Weekly activity report
    Wellall
    You are dismissed
    You really love me? he he
    Message body:
    Empty.
    Attachment:
    A ZIP file with a random name, with a file size of 15994 bytes. The zipped file contains an EXE file with a random name and and Excel icon.
    Installation
    Once launched, the worm copies itself and all components to the Windows system directory under the names ‘readme.exe’, ‘onde.exe’, doc.exe’ and ‘readme.exeopen’ and then registers ‘readme.exe in the system registry auto-run key:
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    "gouday.exe" = "%system%\readme.exe"]
    Also creates the following registry key:
    [HKCU\SOFTWARE\DataTime3]
    and saves its variables there.
    The worm attempts to connect to a number of remote sites, storing information about the infected machine on theses sites.
    On launching, the worm launches the MS Notepad (notepad.exe).
    Propagation
    The worm searches for files with the following extensions:
    adb
    asp
    cfg
    dbx
    eml
    htm
    html
    mdx
    mmf
    nch
    ods
    php
    pl
    sht
    txt
    wab
    and send itself to all email addresses found in these files. The worm uses its own SMTP server to send email.
    Remote administration
    The worm opens and monitors port 2745. A backdoor function means that commands can then be executed and files can be downloaded on the victim computer, with all of this being done from a remote location.
    Other
    The worm attempts to block antivirus database updates by terminating the following processes:
    ATUPDATER.EXE
    ATUPDATER.EXE
    AUPDATE.EXE
    AUTODOWN.EXE
    AUTOTRACE.EXE
    AUTOUPDATE.EXE
    AVLTMAIN.EXE
    AVPUPD.EXE
    AVWUPD32.EXE
    AVXQUAR.EXE
    CFIAUDIT.EXE
    DRWEBUPW.EXE
    ICSSUPPNT.EXE
    ICSUPP95.EXE
    LUALL.EXE
    MCUPDATE.EXE
    NUPGRADE.EXE
    NUPGRADE.EXE
    OUTPOST.EXE
    UPDATE.EXE
    Bagle.d is programmed to stop propagating after March 14, 2004.

    Related Posts

  • Email-Worm.Win32.Bagle.d
  • Email-Worm.Win32.Bagle.e
  • I-Worm.Bagle.a
  • Email-Worm.Win32.Bagle.c
  • Email-Worm.Win32.Bagle.c
  • Leave a Reply

    I-Worm.Bagle

    Details
    I-Worm.Bagle.c
    This worm spreads via the Internet in the form of an attachment to infected emails.
    The worm itself is a PE EXE file of approximately 15KB, compressed using UPX. The size of the decompressed file is approximately 28KB.
    Characteristics of infected messages
    Message header:
    Accounts department
    Ahtung!
    Camila
    Daily activity report
    Flayers among us
    Freedom for everyone
    From Hair-cutter
    From me
    Greet the day
    Hardware devices price-list
    Hello my friend
    Hi!
    Jenny
    Jessica
    Looking for the report
    Maria
    Melissa
    Monthly incomings summary
    New Price-list
    Price
    Price list
    Pricelist
    Price-list
    Proclivity to servitude
    Registration confirmation
    The account
    The employee
    The summary
    USA government abolishes the capital punishment
    Weekly activity report
    Wellall
    You are dismissed
    You really love me? he he
    Message body:
    Empty.
    Attachment:
    A ZIP file with a random name, with a file size of 15994 bytes. The zipped file contains an EXE file with a random name and and Excel icon.
    Installation
    Once launched, the worm copies itself and all components to the Windows system directory under the names ‘readme.exe’, ‘onde.exe’, doc.exe’ and ‘readme.exeopen’ and then registers ‘readme.exe’ in the system registry auto-run key:
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    "gouday.exe" = "%system%\readme.exe"]
    Also creates the following registry key:
    [HKCU\SOFTWARE\DataTime2]
    and saves its variables there.
    The worm attempts to connect to a number of remote sites, storing information about the infected machine on theses sites.
    Bagle.c executes the default Windows ‘Notepad’ program, notepad.exe, tricking users into believing the program they just executed “does something”.
    Propagation
    The worm searches for files with the following extensions:
    adb
    asp
    cfg
    dbx
    eml
    htm
    html
    mdx
    mmf
    nch
    ods
    php
    pl
    sht
    txt
    wab
    and send itself to all email addresses found in these files. The worm uses its own SMTP server to send email.
    Remote administration
    The worm opens and monitors port 2745. A backdoor function means that commands can then be executed and files can be downloaded on the victim computer, with all of this being done from a remote location.
    Other
    The worm attempts to block antivirus database updates by terminating the following processes:
    ATUPDATER.EXE
    ATUPDATER.EXE
    AUPDATE.EXE
    AUTODOWN.EXE
    AUTOTRACE.EXE
    AUTOUPDATE.EXE
    AVLTMAIN.EXE
    AVPUPD.EXE
    AVWUPD32.EXE
    AVXQUAR.EXE
    CFIAUDIT.EXE
    DRWEBUPW.EXE
    ICSSUPPNT.EXE
    ICSUPP95.EXE
    LUALL.EXE
    MCUPDATE.EXE
    NUPGRADE.EXE
    NUPGRADE.EXE
    OUTPOST.EXE
    UPDATE.EXE
    Bagle.c is programmed to stop propagating after March 14, 2004.

    Related Posts

  • Email-Worm.Win32.Bagle.d
  • Email-Worm.Win32.Bagle.e
  • I-Worm.Bagle.a
  • Email-Worm.Win32.Bagle.c
  • Email-Worm.Win32.Bagle.c
  • Leave a Reply

    I-Worm.Bagle

    Details
    I-Worm.Bagle.b
    This worm spreads via the Internet in the form of an attachment to infected emails.
    The worm itself is a PE EXE file of approximately 11KB, compressed using UPX. The size of the decompressed file is approximately 16KB.
    Characteristics of infected messages:
    Message header:
    ID xall thanks
    with x being a string of random characters.
    Message body:
    Yours ID x

    Thank
    with x being a string of random characters.
    Attachment:
    The attachment has a random name, with a file size of 11KB.
    Installation
    Once launched, the worm copies itself to the Windows system directory under the name ‘au.exe’ and registers this file in the system registry auto-run key:
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    “au.exe” = “%system%\au.exe”
    Also creates the following registry key:
    [HKCU\SOFTWARE\Windows2000]
    and saves its variables there.
    The worm attempts to connect to a number of remote sites, all of which are in some way connected with the Trojan proxy server TrojanProxy.Win32.Mitglieder.
    On launching, the worm launches the Sound Recorder utility (sndrec32.exe).
    Propagation
    The worm searches for files with the following extensions: wab, txt, htm, html and send itself to all email addresses found in these files. The worm uses its own SMTP server to send email.
    Remote administration
    The worm opens and monitors port 8866. A backdoor function means that commands can then be executed and files can be downloaded on the victim computer, with all of this being done from a remote location:
    Other
    The worm is programmed to stop propagating after 25th February 2004.

    Related Posts

  • Email-Worm.Win32.Bagle.d
  • Email-Worm.Win32.Bagle.e
  • I-Worm.Bagle.a
  • Email-Worm.Win32.Bagle.c
  • Email-Worm.Win32.Bagle.c
  • Leave a Reply

    I-Worm.Bagle

    Details
    I-Worm.Bagle.a
    This worm spreads via the Internet in an attachment to infected emails.
    The worm itself is a Window PE EXE file of approximately 15KB.
    Messages sent by the worm have the following characteristics:
    From:
    random sender
    Subject:
    Hi
    Body:
    Test =)
    Signature:
    Test, yep
    Attach:
    random name
    Installation
    The worm is activated only if a user clicks on the attached file. When installing, the worm copies itself to the system directory under the name 'bbeagle.exe' and registers this file in the system registry auto-run key:
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    “d3dupdate.exe” = “%system%\bbeagle.exe”
    The worm will also run the Windows application calc.exe.
    The worm attempts to connect to several remote sites relating to TrojanProxy.Win32.Mitglieder.
    Replication
    The worm looks for files with the extensions wab, txt, htm, html, r1 and scans them for email-like text strings, then sends infected messages to the email addresses found.
    The worm uses an SMTP engine to send infected messages.
    Backdoor function
    The worm opens port 6777 to listen for commands. The backdoor function allows the attacker to download files and execute commands on the infected computer.
    Other
    If the system date is later than 28th January 2004, the worm will not have any effect.

    Related Posts

  • Email-Worm.Win32.Bagle.d
  • Email-Worm.Win32.Bagle.e
  • I-Worm.Bagle.a
  • Email-Worm.Win32.Bagle.c
  • Email-Worm.Win32.Bagle.c
  • Leave a Reply


    Spyware Removal Spyware Protection Tools