Content
W32/Bagle.r@MM
- Type
- Virus
- SubType
- E-mail worm
- Discovery Date
- 03/18/2004
- Length
- 25,600 Bytes
- Minimum DAT
- 4340 (03/22/2004)
- Updated DAT
- 5090 (08/03/2007)
- Minimum Engine
- 5.1.00
- Description Added
- 03/17/2004
- Description Modified
- 03/18/2004 1:54 PM (PT)
Risk Assessment
- Corporate User
- Low-Profiled
- Home User
- Low-Profiled
Tab Navigation
Characteristics
- Update March 18th 2004 08:25 PST --
This threat has been deemed Low-Profiled due to media attention at the following site:
http://zdnet.com.com/2100%2D1105%2D5175172.html
--
This variant is very similar to W32/Bagle.q@MM
Please note: This variant does not parasitically infect files.
Symptoms
- direct.exe (25,600 bytes)
- direct.exeopen (26,682 bytes)
For further details please see the description of W32/Bagle.q@MM .
Method of Infection
Please see the description of W32/Bagle.q@MM for further details.
Removal
All Users
:
Use specified engine and DAT files
for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Detection for the email message containing the exploit is included (for gateway products and the email scan plugins in point products) as W32/Bagle.eml!mso3-032 .
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Characteristics
Characteristics -
- Update March 18th 2004 08:25 PST --
This threat has been deemed Low-Profiled due to media attention at the following site:
http://zdnet.com.com/2100%2D1105%2D5175172.html
--
This variant is very similar to W32/Bagle.q@MM
Please note: This variant does not parasitically infect files.
Symptoms
Symptoms -
- direct.exe (25,600 bytes)
- direct.exeopen (26,682 bytes)
For further details please see the description of W32/Bagle.q@MM .
Method of Infection
Method of Infection -
Please see the description of W32/Bagle.q@MM for further details.
Removal -
Removal -
All Users
:
Use specified engine and DAT files
for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Detection for the email message containing the exploit is included (for gateway products and the email scan plugins in point products) as W32/Bagle.eml!mso3-032 .
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A