All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
Virus Encyclopedia
Riskware
Alerts
Analysis
News
Glossary
Weblog

 
Archive

<< 2010  
Jan Feb  
     
     
     
Virus Alert Danger Levels
Virus Alert Danger Levels

Wonder what the current virus alert means for your computer? Find out more about our Virus Alerts Threat Levels.

Free Removal Tools
Free Removal Tools

The Kaspersky Lab website removal tools section provides free utilities for removing dangerous viruses during an epidemic.

Antivirus Database Updates
Antivirus Database Updates

Kaspersky Anti-Virus users can always find the latest virus definitions in the database updates on the Kaspersky website.

 

  Home / Viruses / Alerts

Email-Worm.Win32.Bagle.bo

05.31.05 15:35 GMT   |  comments (1)

Status : moderate risk

Kaspersky Lab has detected several new versions of Bagle. Most of them are detected as Bagle.bo, with others being detected as Bagle.bp.

The first version of Bagle.bo was widely spammed on 31st May. Bagle.bo is almost identical to previous versions of the worm; however, a different packer is used. Since the initial spamming, another 8 versions have been released. Bagle.bo variants differ from each other only in terms of the packer used to compress the worm file.

The worm arrives as an attachment to infected messages. The content of these messages, and the name of the ZIP attachment are random. The attachment contains the worm's executable file - examples of file names include 03_05_2005.exe, 01_05_2005.exe and 19_04_2005.exe. These ZIP files are about 17KB in size, while Bagle.bo is approximately 36KB in size.

Bagle.bo variants include a list of URLs which will be checked periodically. Files placed on these sites may be new versions of Bagle, or other malicious programs which can then be installed on the victim machine. Bagle.bp is downloaded by Bagle.bo from one of these sites.

Urgent updates have been released to provide protection against all the new Bagle versions. Users are strongly recommended to download the latest updates.

A detailed description of Email-Worm.Win32.Bagle.bo is available in the Virus Encyclopaedia.

Related links
Analysis
Malware Evolution: April Roundup
The Bagle botnet
Malware Evolution: October Roundup
Malware Evolution: July Roundup
Malware Evolution: May Roundup
Blog
Meanwhile, on the other side of the galaxy...
An increase in the Bagle activity
Bagle's birthday
No rest for the Bagles - or for the virus analysts
And another Bagle
Alerts
Email-Worm.Win32.Bagle.fy
Email-Worm.Win32.Bagle.fj
Trojan-Downloader.Win32.Bagle.f
Email-Worm.Win32.Bagle.eb
Email-Worm.Win32.Bagle.cx-dw
 

Copyright © 1996 - 2010
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com