Home  l  Role & Plan  l  News & Updates  l  Policies  l  Helpdesk  l  Sections  l  Asset Systems  l  Location  l  Cisco Academy  l  
USP Home » Information Technology Services » Helpdesk » Computer Security Defences » W32/Bagle.az@MM worm

Print

» Services
» Guides
» USP Computer Standards
» Forms
» FAQ
» Computer Security Defences
Virus FAQ
Installing Windows Updates
Running Windows Security Patches
W32/Korgo.x worm
W32/Bagle.az@MM worm
Installing and configuring Spybot
Running Spybot
Running Stinger
Scanning your PC for Virus
» Software Downloads
» Training

Quick Links
» Lab Bookings
» W32/Korgo.x worm
» W32/Bagle.ag@MM worm
» Staff Dialup Access
» Security Tips




W32/Bagle.az@MM worm

Name of virus: W32/Bagle.az(at)MM was updated to Medium on 28 Sept 2004 due to prevalence

Type of virus: Mass-mailing worm

Systems Affected: Windows98, Windows ME, Windows NT, Windows 2000, Windows XP, Windows 2003 Server

What does it do?

This is a mass-mailing worm with the following characteristics:

  1. contains its own SMTP engine to construct outgoing messages
  2. harvests email addresses from the victim machine 
  3. the From: address of messages is spoofed 
  4. contains a remote access component 
  5. copies itself to folders that have the phrase shar in the name (such  as common peer

Mail Propagation:

The details are as follows:
From : (address is spoofed)  Subject : 
Re:
 
Re: Hello
 
Re: Thank you!
 
Re: Thanks :)
 
Re: Hi
 
Body Text: 
:)
 
:))
 
Attachment: (with an extension of .exe, .scr, .com or .cpl) 
Price  
price  
Joke
 

Removal Instructions:

  1. Download Stinger utility. Click here for instructions on downloading Stinger and running Stinger.
  2. Run Stinger to scan and clean the incidents of the W32/Bagle.az(a)MM worm.

For our Centre users, you can contact your IT personnel for assistance. If you have any difficulties, please contact our Helpdesk on Ext 2117.


Disclaimer & Copyright l Contact Us l 
© Copyright 2004. All Rights Reserved.
Page updated: Wednesday, September 29, 2004
The University of the South Pacific
Laucala Campus, Suva, Fiji
Tel: +679 331 3900