Bagle.AM is a worm that opens a TCP port and listens to it, allowing remote access to the affected computer. It also ends processes belonging to several antivirus update programs, among other applications, and it attempts to download a fake JPG file from several websites. Bagle.AM spreads via email, in a message containing an attached file with a random name and a ZIP extension. This file contains an HTML file and a hidden EXE file, which is run when the user opens the HTML file. Additionally, Bagle.AM also spreads through peer-to-peer (P2P) file sharing programs. |