VIRUS ADVISORY - W32/Bagle.u@MM
Main News March 28th, 2004
The latest variant of W32/Bagle@MM, W32/Bagle.u@MM is a Medium Risk mass-mailing worm that:1) installs a dangerous backdoor Trojan-horse program that opens TCP port 4751, 2) opens the Windows game Hearts (if present on the system), and 3) sends itself to email addresses addresses stolen from an infected machine. It arrives as an attachment in an email with a blank subject line and blank body text.
Up-to-date McAfee VirusScan users with dat 4344 are protected from this threat.
Note: Receiving an email alert stating that the virus came from your email address is not an indication that you are infected—the virus often spoofs the “from” address.
What to look for:
FROM: Varies (spoofed - using one of the harvested email addresses from the infected system). Go to our site to see a list of files this worm uses to harvest email addresses.
SUBJECT: Blank.
BODY: Blank.
ATTACHMENT: Varies. Randomly named executable, with an .EXE extension.
Related Posts
NASA finds a virus on a computer in International Space Station!
Russian stock exchange hit by virus attack
Metal Gear.a Virus targeting Symbian Phones
USA gets taste of first Mobile Virus with Cabir
Matsushita to pay for the Nokia mobile phone battery recall

About










Leave a Comment