martymas Posted January 28, 2005 Report Share Posted January 28, 2005 hi team another bagel virus is on the loose out there.it is raging in the south pacific.but dosent mention that in this news letter .how ever where ever it is.take plenty of precautions .martyTo read an HTML version of this newsletter, go to: http://www.trendmicro.com/en/security/report/overview.htmIssue Preview: 1. Trend Micro Updates - Pattern File & Scan Engine Updates2. Return of BAGLE – WORM_BAGLE.AZ (Medium Risk)3. Top 10 Most Prevalent Global Malware 4. Submit your Spam & Suspicious Files for Analysis5. Webinar: Protect your Growing Business from Viruses and Malicious CodeNOTE: Long URLs may break into two lines in some mail readers. Should this occur, please copy and paste the URL into your browser window.************************************************************************1. Trend Micro Updates - Pattern File & Scan Engine Updates ------------------------------------------------------------------------PATTERN FILE: 2.375.00 http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VRSCAN ENGINE: 7.500 http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VS2.Return of BAGLE – WORM_BAGLE.AZ (Medium Risk)------------------------------------------------------------------------WORM_BAGLE.AZ is another variant in the BAGLE family. This wormarrives as an email attachment, and once executed, it sends copies of itself to allemail addresses it gathers from files with certain extensions, and skips those addresses that contain particular strings. The email it sends isspoofed, and may appear to have come from a familiar email address. The worm drops acopy of itself into the Windows system folder, and looks for folders that havethe string "shar", then drops copies of itself using file names with.EXE extensions (it assumes that these folders are shared). In addition, this wormdisplays various icons and terminates several processes, most of which are relatedto antivirus and security programs. This worm ceases to perform most of itsmaliciousroutines on April 25, 2006 or later. It is currently spreadingin-the-wild and infecting computers running Windows 95, 98, ME, 2000, and XP.Upon execution, this worm drops a copy of itself using the following filenames into the Windows system folder:sysformat.exe sysformat.exeopen sysformat.exeopenopen It then creates two registry entries. One registry enty allows it toexecute at every Windows startup. By adding this entry, it enters an infinite loopin 100-millisecond intervals. As a result, this worm can never be deletedas long as it is in memory. The second registry entry is used to determine how longit has executed on a system. If this registry entry indicates that it is 25days from its first execution, this worm uninstalls itself from the system. It alsouninstalls itself when the system date is April 25, 2006 or later.It looks for folders that have the string "shar" and drops copies ofitself using the following file names:1.exe 2.exe 3.exe 4.exe 5.scr 6.exe 7.exe 8.exe 9.exe 10.exe Ahead Nero 7.exe Windown Longhorn Beta Leak.exe Opera 8 New!.exe XXX hardcore images.exe WinAmp 6 New!.exe WinAmp 5 Pro Keygen Crack Update.exe Adobe Photoshop 9 full.exe Matrix 3 Revolution English Subtitles.exe ACDSee 9.exe This worm attempts to propagate via email using its own Simple MailTransfer Protocol (SMTP) engine. It searches for email addresses with certainextensions. View the full list of extensions at: http://www.trendmicro.com/vinfo/virusencyc...LE%2EAZ&VSect=T.It sends email with the following details:Subject: (any of the following) Delivery service mail Delivery by mail Registration is accepted Is delivered mail You are made active Message body: (any of the following) Thanks for use of our software. Before use read the help Attachments: (any of the following file names) guupd02 Jol03 siupd02 upd02 viupd02 wsd01 zupd02 (with any of the following extensions) COM CPL EXE SCR The worm skips email addressess that contain certain strings. Itterminates specific processes, mostly related to antivirus and security programs. It alsoattempts to connect to, and download files from, certain Web sites. For the completelist of strings, processes and Web sites, visit http://www.trendmicro.com/vinfo/virusencyc...LE%2EAZ&VSect=T.Several registry entries associated with WORM_NETSKY variants are alsodeleted, and mutexes are created to prevent NETSKY variants from running on the systemsalready infected with this BAGLE worm.This worm opens opens a port and listens for commands coming from a remotemalicious user. It executes these commands on an infected system, providing theremote malicious user virtual control over the system.If you would like to scan your computer for WORM_BAGLE.AZ or thousandsof other worms, viruses, Trojans and malicious code, visit HouseCall, Trend Micro's free, online virus scanner at: http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VTWORM_BAGLE.AZ is detected and cleaned by Trend Micro pattern file#2.375.00 and above. For additional information about WORM_BAGLE.AZ please visit: http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VU3. Top 10 Most Prevalent Global Malware (from January 21 to January 27, 2005)------------------------------------------------------------------------1. WORM_NETSKY.P2. HTML_NETSKY.P3. JAVA_BYTEVER.A4. WORM_NETSKY.D5. SPYW_GATOR.D6. WORM_NETSKY.B7. WORM_NETSKY.C8. DOS_AGOBOT.GEN9. SPYW_GATOR.C10. TROJ_ISTBAR.GM4. Submit your Spam & Suspicious Files for Analysis------------------------------------------------------------------------ Found a file on your computer, with a strange name, and it's not detectedas malware? Tired of getting spam email? Send it to us, for our engineers to analyze.Submit your spam for analysis:http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VWSubmit a suspicious file or undetected virus for analysis:http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VY5. Webinar: Protect your Growing Business from Viruses and Malicious Code------------------------------------------------------------------------Please join in on February 8 from 11:00 a.m. - noon (Pacific Time),for a stimulating presentation on how Trend Micro, HP, and Microsoft are working together toaddress the Small and Medium Business (SMB) Infrastructure and Internet securityneeds. Presenters include:Bala Venkat, Sr. Product Marketing Manager (SMB segment), Trend MicroHarry Brelsford, Founder, SMB NationMarc Semadeni, Global Product Marketing Manager, Hewlett-PackardDuring this presentation, you’ll learn about: -Trend Micro SMB security offerings, and how they can protect yourbusiness from threats of viruses, and spam-The unique Trend Micro SMB value proposition and key competitivedifferentiators-Trend Micro SMB programs -Extending Microsoft Small Business Server 2003 (SBS) with Trend Micro Client/Server/Messaging Suite for SMB (CSM for SMB)-CSM for SMB features that work nicely with SBS 2003 server-The turnkey solution – HP ProLiant server with Microsoft SBS 2003 andTrend Micro CSM for SMB as the fastest, easiest, most reliable and least expensivesolution on a trusted, industry-standard server platformRegister online at:https://trendmicro.webex.com/trendmicro/myw...961531197605092***********************************************************************************______________________________________________________________________This message was sent by Trend Micro's Newsletters Editor using ResponsysInteract .To unsubscribe from Trend Micro's Newsletters Editor: http://trendnewsletter.rsc03.net/servlet/o...RFpgLmDgLmDgSE0To update your subscription preference, or to change your email address:http://trendnewsletter.rsc03.net/servlet/w...pkNlyLihkm_U_VBTo view our permission marketing policy: http://www.rsvp0.netCopyright 1989-2004 Trend Micro, Inc. All rights reservedTrend Micro, Inc., 10101 N. De Anza Blvd., Suite 200, Cupertino, CA95014 Quote Link to post Share on other sites
tg1911 Posted January 28, 2005 Report Share Posted January 28, 2005 Thanks for the heads-up, Marty. Quote Link to post Share on other sites
rv56 Posted January 28, 2005 Report Share Posted January 28, 2005 Thanks for the look out and sharing this info. Marty........ Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.