Main Menu
Home
Bookmark
Contact Us



 
I-Worm.Bagle.a Viruses Information

Name: I-Worm.Bagle.a
Category: Viruses
Description: Details
I-Worm.Bagle.an

This worm spreads via the Internet as an attachment to infected emails, and also via file-sharing networks.
It is almost identical to I-Worm.Bagle.al
It is compressed using PEX; the compressed file is 18436 bytes in size, and the uncompressed file is 24068 bytes in size.
Propagation via email
Infected messages:
Message header:
photo
Message body:
photo
The message body appears as an HTML page.
Attachment name:
foto.zip
fotos.zip
Attachment contents:
fotofoto.html fotofotofoto1.exe
The first file contains Exploit.CodeBaseExec
The second file contains TrojanDropper.Win32.Small.kv, which installs TrojanDownloader.Win32.Agent.cj on the victim machine. This program then downloads the main module of the worm.
Remote administration
The worm opens port 82 and listens for commands. This makes it possible for the author of the worm to download and launch files on the victim machine.
Other
File names, registry key values and the routines for propagating via file-sharing networks are identical to those of I-Worm.Bagle.al
The worm is programmed to cease functioning and to delete itself after 2nd September 2004.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Dy.27
Worm.P2P.Tanked.
ELCN.37
Worm.Shor
Macro.Word97.Bismar
Spartak.110
Simbioz.33
Trojan.SymbOS.Mosquit.
Pitch.59
KPI.32


 


© 2006-2008 spyware32.com - Privacy Policy