Slashdot Mirror


'Bagle' Worm Heading For A Windows PC Near You

mrSinclair writes "the 'Bagle' or 'Beagle' worm is expected to hit the U.S. by midweek, probably Tuesday as many employees return from a three-day weekend." He points to this Washington Post story (via Yahoo!), which describes the Windows mass-mailing worm as being transmitted via email as an .exe attachment and as installing "a program that lets attackers connect to infected machines, install malicious software or steal files." The article says Bagle has been detected in more than 100 countries. Other readers have sent in links to coverage at the BBC and at SearchSecurity.com.

5 of 606 comments (clear)

  1. Interesting Tidbit by jmt9581 · · Score: 5, Informative

    It looks like the writers of the virus DOS'ed themselves (from the aformentioned Yahoo! article):

    Bagle also tries to download an unknown program from one of more than 30 Web sites located mostly in Germany and Russia. None of those Web sites was reachable as of Monday afternoon.

    Or is it more likely that these servers in Russia and Germany were also hacked and were just being used?

    In any rate, this doesn't look so bad. The searchsecurity.com article says that "Removing the worm manually is just a matter of killing "bbeagle.exe" in the Task Manager. The registry keys created by the worm also need to be removed." Hopefully this one won't be as bad as Sobig. :)

    --

    My blog

  2. It's already here (My story) by Trillian_1138 · · Score: 5, Informative

    I'm the resident geek in my dorm, and have spent the last 24 hours getting rid of it on computers of anyone and everyone. The particular strain we saw came in an email with the subject of simply "Hi" and contained (basically) the following test.

    Hi!
    This is a test.
    (random string of letters)
    Testy test.

    The attached file was a modified version of the Windows calculator which (according to the Symantec site) "Emails all the contacts it can find inside files with the extensions .wab, .htm, .html, and .txt"

    It's interesting because apparently that's ALL it does. It doesn't screw with files or settings, or run malicous code (outside the actual act of reproducing itself). It's annoying, however, because it sends emails to people who are NOT in your address book, but merely mentioned in text files somewhere on your computer. In the last 24 hours I've gotten emails with the virus from friends, random people in my university, at least one university email address that should have been run by someone who knew better, and a couple random friends-of-friends.

    Also, according to Symantec, it dies on the 28th.

    It was really interested to see the spread at my college. For us, it began around 1 AM Monday morning, peaked around 2, and was already slacking off by 3 AM. I know this from my own inbox, people in my dorm, and talking to people elsewhere.

    I do find it currious the virus didn't DO anything. Is it just someone screwing around, a test for a future release or (as some of the more paranoid people in my dorm are suggesting) a released virus by the anti-virus companies to keep people in enough fear to demand their products.

    As a side note, I also spent hours cleaning the assorted spyware and adware that builds up when people don't know how to properly use their computers....more than one person could literaly not do work becasue of the porn popups that plagued their computer.

    -Trillian

  3. Re:Antivirus Company Submissions by Neva · · Score: 5, Informative

    F-Secure detects it, since yesterday. There's a removal tool there too.

    Bagle description

  4. NAV already detects it... by antdude · · Score: 5, Informative

    ... according to Symantec's Security Response (since 1/18/2004).

    --
    Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
  5. Re: AVG's got it... by MachDelta · · Score: 5, Informative

    ...since yesterday, apparently. Good to see Grisoft keeping AVG up to date.
    Oh, and they've got a little blurb on the virus too.