Bagle variants spreading fast
Bagle variants spreading fast
R E L A T E D   C O N T E N T
ADVERTISEMENT

Three more Bagle variants on the loose

Latest mutations disable antivirus and security tools

Steve Ranger, vnunet.com 01 Mar 2005
ADVERTISEMENT

Three newly discovered variants of the Bagle virus are running wild on the internet, security experts warned today.

IT security company F-Secure said that Bagle BB, BD and BE are spreading fast. The firm's senior security consultant Patrik Runald added that there is a "strong possibility" that the same person is behind all three.

Bagle BB was spammed out in email overnight to as many as 100,000 people. F-Secure has issued a 'level two' alert about Bagle BB, which is a Trojan downloader.

This variant does not send emails from infected machines, but drops files like 'winshost.exe' and 'wiwshost.exe' and attempts to disable a range of antivirus and security tools.

"Any Trojan which turns off your antivirus or firewall can open you up to further attack, even by very old viruses," said Graham Cluley, senior technology consultant at Sophos.

"My advice is keep your antivirus automatically updated and always be suspicious of unsolicited email attachments."

Bagle BB also overwrites the host file with entries to prevent access to a number of antivirus websites, and tries to download an executable named 'zo2.jpg' from dozens of different download sites.

"As usual, most of these download sites do not contain such a file now, but at a later date they will contain different spam proxies or backdoors," warned F-Secure.

The Bagle BD variant works in a similar way, while the BE variant spreads in a more traditional way by email, said Runald.

But rather than harvesting email addresses from the infected machine to spread further, this variant accesses a web server on the internet. Bagle BD also tries to install a backdoor into infected machines.

See also:

Alliance aims to 'spread cyber-terror'Bagle, Zafi and Netsky coders thought to be working together  08 Mar 2005
Downloader attempts to disable antivirus and security toolsSecurity firm ups risk assessment as virus onslaught gathers pace  02 Mar 2005
Bagle BM mutant strikesSecurity firm predicts new wave of virus attacks  01 Mar 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities