Encyclopedia

Bagle.AM

 
Threat LevelHigh threatDamageSevereDistributionNot widespread
Common name:Bagle.AM
Technical name:W32/Bagle.AM.worm
Threat level:Medium
Alias:W32/Bagle.aq!zip, WORM_BAGLE.AC, I-Worm.Bagle.al, W32/Bagle.aq@MM
Type:Worm
Effects:  

It opens a TCP, it ends processes belonging to antivirus update programs, among others, and it attempts to download a fake JPG file from several websites. It spreads via email and through P2P programs.

Affected platforms:

Windows XP/2000/NT/ME/98/95

First detected on:Aug. 9, 2004
Detection updated on:Nov. 5, 2004
StatisticsNo
Yes, using TruPrevent Technologies
Repair utility: Panda QuickRemover

Brief Description 

    

Bagle.AM is a worm that opens a TCP port and listens to it, allowing remote access to the affected computer. It also ends processes belonging to several antivirus update programs, among other applications, and it attempts to download a fake JPG file from several websites.

Bagle.AM spreads via email, in a message containing an attached file with a random name and a ZIP extension. This file contains an HTML file and a hidden EXE file, which is run when the user opens the HTML file.

Additionally, Bagle.AM also spreads through peer-to-peer (P2P) file sharing programs.

Visible Symptoms 

    

Bagle.AM is difficult to recognize, as it does not display any messages or warnings that indicate it has reached the computer.

However, when Bagle.AM spreads via email, it reaches the computer in a message with the following characteristics:

  • Subject: it is empty.
  • Message:
    new price
  • Attachments:
    The attached file has a random name and a ZIP extension, which contains an HTML file and a hidden EXE file.

Last updated:  05/11/2004 

Virus News

3/10/09.-More than 10 Million Worldwide Were Actively Exposed to Identity Theft in 2008

3/5/09.-Cyber-crooks manipulate Internet searches to sell fake antivirus products

3/2/09.-VideoPlay adware infections grew 400% in February through malicious use of Web 2.0 pages

[+ Noticias]