Content

W32/Bagz.d@MM

Type
Virus
SubType
E-mail worm
Discovery Date
10/19/2004
Length
157,186 bytes (EXE)
153,007 bytes (ZIP)
Minimum DAT
4400 (10/20/2004)
Updated DAT
5791 (11/03/2009)
Minimum Engine
5.1.00
Description Added
10/19/2004
Description Modified
10/19/2004 10:52 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This variant of W32/Bagz@MM is similar to previous variants (for example W32/Bagz.b@MM ), bearing the following characteristics:

  • it is packed with UPX
  • consists of multiple file components
  • constructs messages using its own SMTP engine, attaching itself as an EXE (sometimes within a ZIP archive)
  • disables/uninstalls certain security/AV products from the victim machine
  • overwrites the local hosts file (to prevent certain products from updating correctly)

Symptoms

  • Local hosts file overwritten as described below
  • Outgoing messages matching these characteristics

The worm drops the following files when executed:

  • %WinDir%\SYSTEM32\RPC32.EXE (123,904 bytes)
  • %WinDir%\SYSTEM32\RUN32.EXE (9,728 bytes)
  • %WinDir%\SYSTEM32\SYSBOOT.DOC (many spaces) .EXE (157,187 bytes)

The RPC32.EXE file is installed as service on the victim machine, with the following properties:

Display Name: Network Explorer
Image Path: %WinDir%\SYSTEM32\RPC32.EXE
Description: Starts and configures accessibility tools from one window

The service is installed to start automatically at system startup.

Note: The 9,728 byte component (RUN32.EXE) is detected as W32/Bagz!proxy since the 4397 DATs.

Method of Infection

Mail Propagation

The virus harvests target email addresses from the victim machine, from the following filetypes:

  • .TBB
  • .tbb
  • .TBI
  • .tbi
  • .DBX
  • .dbx
  • .HTM
  • .htm
  • .TXT
  • .txt

Email addresses containing any of the following strings will not be targetted:

  • winzip
  • winrar
  • webmaster@
  • update
  • unix
  • support@
  • support
  • spam
  • sopho
  • samples
  • root@
  • rating@
  • postmaster@
  • pgp
  • panda
  • ntivi
  • noreply
  • noone@
  • nobody@
  • news
  • netadmin@
  • local
  • listserv
  • linux
  • kasp
  • info@
  • icrosoft
  • hostmaster@
  • help@
  • google
  • gold-certs@
  • gold-
  • free-av
  • feste
  • f-secur
  • contract@
  • contact@
  • certs@
  • certific
  • cafee
  • bugs@
  • bsd
  • anyone@
  • all@
  • administrator@
  • admin
  • abuse
  • @microsoft
  • @messagelab
  • @iana
  • @foo
  • @avp
  • oocies

Outgoing messages are constructed as follows:

Subject: Any of the following:

  • ASAP
  • please responce
  • Read this
  • urgent
  • toxic
  • contract
  • Money
  • office
  • Have a nice day
  • Hello
  • Russian's
  • Amirecans
  • attachments
  • attach
  • waiting
  • best regards
  • Administrator
  • Warning
  • text
  • Vasia
  • re: Andrey
  • re: please
  • re: order
  • Allert!
  • Att

Message Body: Uses one of the following message bodies.

  • Did you get the previous document I attached for you? I resent it in this email just in case, because I really need you to check it out asap.

    Best Regards
  • I made a mistake and forgot to click attach on the previous email I sent you. Please give me your opinion on this opportunity when you get a chance.

    Best Regards
  • I was supposed to send you this document yesterday. Sorry for the delay, please forward this to your family if possible. It contains important info for both of you.
  • Sorry, I forgot to send an important document to you in that last email. I had an important phone call. Please checkout attached doc file when you have a moment.

    Best Regards
  • I was in a rush and I forgot to attach an important document. Please see attached doc file.

    Best Regards,
  • I am responding to your last email in the attached file. Please get back to me if there is any problem reading the attachment.
  • I had a delivery problem with your inbox, so maybe you'll receive this now. For some reason, I received only part of your last several emails. I want to make sure that there are no problems with either of our accounts. it was previously blocked by your email filters.

    Please view the attachment and respond.
    Thanks
  • it was previously blocked by your email filters. Please read the attachment and respond.
    Thanks
  • My system crashed last weekend and I lost most of my friends and work contacts. Please check the attached (.pdf) and please let me know if your info is current.
  • The reason is that I am not currently added to your "allowed" contact list. Please add my updated contact info provided in the attached (.pdf) file so I can send you emails in the future.
    Sincerely
  • See the (.pdf) file attached and please respond if you have any questions.
  • Please verify your mailing address on file is correct. We have attached a (.pdf) sheet for you to use for your response.
  • Our contact information has changed. See the attached (.pdf) sheet for details.

    Sincerely,
  • Due to your failure to comply with our email Rules and Regulations, your email account has been temporarily suspended for 24 hours unless we are contacted regarding this situation. You must read the attached document for further instructions. Failure to comply will result in termination of your account.
    Regards,
    Net Operator
  • ***URGENT: SERVICE SHUTDOWN NOTICE***

    You are currently unable to send emails. This may be a billing issue. Please call the billing center. The # for the billing office is located in the attached contact list for your convenience.
  • ***ATTENTION: YOUR EMAIL IS NOT BEING DELIVERED!***
    Hello,

    The previous email you sent has been recognized as spam. This means your email was not delivered to your friend or client. You must open the attached file to receive more information.
  • ***YOUR MESSAGE HAS BEEN RECOGNIZED AS SPAM***
    What version of windows you are using? This last document I received from you came out weird. Please see the attached word file and resend the file to me.
    Many thanks,
    User
  • My PC crashed while I was sending that last email. I have re-attached the document of yours that I discovered. Please read attached document and respond ASAP.
    Sincerely,
    User
  • Your email was sent in an INVALID format. To verify this email was sent from you, simply open the attached email (.eml) file and click yes in the sender options box.
    Thank You, User
  • Your email was received.
    YOUR REPLY IS URGENT!
    Please view the attached text file for instructions.
    Regards,
    User
  • I was in a hurry and I forgot to attach an important document. Please see attached.
    Best Regards, User
  • I resent this email as attachment because it was previously blocked by your email filters. Please read the attachment and respond.
    Thanks,User
  • Sorry, I forgot to attach the new contact information. Please view the attached (.pdf) contact sheet.
    Sincerely,
    User

Attachment: May be a ZIP archive or an EXE. If a ZIP attachment, one of the following filenames is used:

  • backup.zip
  • admin.zip
  • archivator.zip
  • about.zip
  • readme.zip
  • help.zip
  • photos.zip
  • payment.zip
  • archives.zip
  • manual.zip
  • inbox.zip
  • docs.zip
  • outbox.zip
  • save.zip
  • rar.zip
  • zip.zip
  • ataches.zip
  • documentation.zip

If an EXE, one of the following filenames is used:

  • backup.doc (many spaces) .exe
  • admin.doc (many spaces) .exe
  • archivator.doc (many spaces) .exe
  • about.doc (many spaces) .exe
  • readme.doc (many spaces) .exe
  • help.doc (many spaces) .exe
  • photos.doc (many spaces) .exe
  • payment.doc (many spaces) .exe
  • archives.doc (many spaces) .exe
  • manual.doc (many spaces) .exe
  • inbox.doc (many spaces) .exe
  • outbox.doc (many spaces) .exe
  • save.doc (many spaces) .exe
  • rar.doc (many spaces) .exe
  • zip.doc (many spaces) .exe
  • ataches.doc (many spaces) .exe
  • documentation.doc (many spaces) .exe
  • docs.doc (many spaces) .exe
  • sysboot.doc (many spaces) .exe

Overwriting of local hosts file

The local hosts file is overwritten, redirecting queries to any of the following remote servers to localhost (127.0.0.1):

  • www3.ca.com
  • www.viruslist.ru
  • www.trendmicro.com
  • www.symantec.com
  • www.networkassociates.com
  • www.nai.com
  • www.my-etrust.com
  • www.sophos.com
  • www.mcafee.com
  • www.kaspersky.ru
  • www.f-secure.com
  • www.fastclick.net
  • www.ca.com
  • www.awaps.net
  • www.avp.ru
  • www.avp.com
  • www.avp.ch
  • windowsupdate.microsoft.com
  • viruslist.ru
  • vil.nai.com
  • us.mcafee.com
  • updates.symantec.com
  • update.symantec.com
  • symantec.com
  • support.microsoft.com
  • spd.atdmt.com
  • sophos.com
  • service1.symantec.com
  • securityresponse.symantec.com
  • secure.nai.com
  • phx.corporate-ir.net
  • office.microsoft.com
  • networkassociates.com
  • nai.com
  • my-etrust.com
  • msdn.microsoft.com
  • media.fastclick.net
  • mcafee.com
  • mast.mcafee.com
  • liveupdate.symantec.com
  • go.microsoft.com
  • ftp.sophos.com
  • ftp.f-secure.com
  • f-secure.com
  • fastclick.net
  • engine.awaps.net
  • downloads.microsoft.com
  • download.microsoft.com
  • download.mcafee.com
  • dispatch.mcafee.com
  • clicks.atdmt.com
  • click.atdmt.com
  • ca.com
  • banners.fastclick.net
  • banner.fastclick.net
  • awaps.net
  • avp.ru
  • avp.com
  • avp.ch
  • atdmt.com
  • ar.atwola.com
  • ads.fastclick.net
  • ad.fastclick.net
  • ad.doubleclick.net

The hosts file is detected (and deleted) as W32/Bagz!hosts with the specified DATs.

Uninstallation of Security Products

The virus carries a large list of filenames which it uses in an attack against existing security products, terminating running processes, and deleting files and Registry keys associated with those products.

Removal

All Users:
Use specified engine and DAT files for detection and removal.

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Characteristics

Characteristics -

This variant of W32/Bagz@MM is similar to previous variants (for example W32/Bagz.b@MM ), bearing the following characteristics:

  • it is packed with UPX
  • consists of multiple file components
  • constructs messages using its own SMTP engine, attaching itself as an EXE (sometimes within a ZIP archive)
  • disables/uninstalls certain security/AV products from the victim machine
  • overwrites the local hosts file (to prevent certain products from updating correctly)

Symptoms

Symptoms -

  • Local hosts file overwritten as described below
  • Outgoing messages matching these characteristics

The worm drops the following files when executed:

  • %WinDir%\SYSTEM32\RPC32.EXE (123,904 bytes)
  • %WinDir%\SYSTEM32\RUN32.EXE (9,728 bytes)
  • %WinDir%\SYSTEM32\SYSBOOT.DOC (many spaces) .EXE (157,187 bytes)

The RPC32.EXE file is installed as service on the victim machine, with the following properties:

Display Name: Network Explorer
Image Path: %WinDir%\SYSTEM32\RPC32.EXE
Description: Starts and configures accessibility tools from one window

The service is installed to start automatically at system startup.

Note: The 9,728 byte component (RUN32.EXE) is detected as W32/Bagz!proxy since the 4397 DATs.

Method of Infection

Method of Infection -

Mail Propagation

The virus harvests target email addresses from the victim machine, from the following filetypes:

  • .TBB
  • .tbb
  • .TBI
  • .tbi
  • .DBX
  • .dbx
  • .HTM
  • .htm
  • .TXT
  • .txt

Email addresses containing any of the following strings will not be targetted:

  • winzip
  • winrar
  • webmaster@
  • update
  • unix
  • support@
  • support
  • spam
  • sopho
  • samples
  • root@
  • rating@
  • postmaster@
  • pgp
  • panda
  • ntivi
  • noreply
  • noone@
  • nobody@
  • news
  • netadmin@
  • local
  • listserv
  • linux
  • kasp
  • info@
  • icrosoft
  • hostmaster@
  • help@
  • google
  • gold-certs@
  • gold-
  • free-av
  • feste
  • f-secur
  • contract@
  • contact@
  • certs@
  • certific
  • cafee
  • bugs@
  • bsd
  • anyone@
  • all@
  • administrator@
  • admin
  • abuse
  • @microsoft
  • @messagelab
  • @iana
  • @foo
  • @avp
  • oocies

Outgoing messages are constructed as follows:

Subject: Any of the following:

  • ASAP
  • please responce
  • Read this
  • urgent
  • toxic
  • contract
  • Money
  • office
  • Have a nice day
  • Hello
  • Russian's
  • Amirecans
  • attachments
  • attach
  • waiting
  • best regards
  • Administrator
  • Warning
  • text
  • Vasia
  • re: Andrey
  • re: please
  • re: order
  • Allert!
  • Att

Message Body: Uses one of the following message bodies.

  • Did you get the previous document I attached for you? I resent it in this email just in case, because I really need you to check it out asap.

    Best Regards
  • I made a mistake and forgot to click attach on the previous email I sent you. Please give me your opinion on this opportunity when you get a chance.

    Best Regards
  • I was supposed to send you this document yesterday. Sorry for the delay, please forward this to your family if possible. It contains important info for both of you.
  • Sorry, I forgot to send an important document to you in that last email. I had an important phone call. Please checkout attached doc file when you have a moment.

    Best Regards
  • I was in a rush and I forgot to attach an important document. Please see attached doc file.

    Best Regards,
  • I am responding to your last email in the attached file. Please get back to me if there is any problem reading the attachment.
  • I had a delivery problem with your inbox, so maybe you'll receive this now. For some reason, I received only part of your last several emails. I want to make sure that there are no problems with either of our accounts. it was previously blocked by your email filters.

    Please view the attachment and respond.
    Thanks
  • it was previously blocked by your email filters. Please read the attachment and respond.
    Thanks
  • My system crashed last weekend and I lost most of my friends and work contacts. Please check the attached (.pdf) and please let me know if your info is current.
  • The reason is that I am not currently added to your "allowed" contact list. Please add my updated contact info provided in the attached (.pdf) file so I can send you emails in the future.
    Sincerely
  • See the (.pdf) file attached and please respond if you have any questions.
  • Please verify your mailing address on file is correct. We have attached a (.pdf) sheet for you to use for your response.
  • Our contact information has changed. See the attached (.pdf) sheet for details.

    Sincerely,
  • Due to your failure to comply with our email Rules and Regulations, your email account has been temporarily suspended for 24 hours unless we are contacted regarding this situation. You must read the attached document for further instructions. Failure to comply will result in termination of your account.
    Regards,
    Net Operator
  • ***URGENT: SERVICE SHUTDOWN NOTICE***

    You are currently unable to send emails. This may be a billing issue. Please call the billing center. The # for the billing office is located in the attached contact list for your convenience.
  • ***ATTENTION: YOUR EMAIL IS NOT BEING DELIVERED!***
    Hello,

    The previous email you sent has been recognized as spam. This means your email was not delivered to your friend or client. You must open the attached file to receive more information.
  • ***YOUR MESSAGE HAS BEEN RECOGNIZED AS SPAM***
    What version of windows you are using? This last document I received from you came out weird. Please see the attached word file and resend the file to me.
    Many thanks,
    User
  • My PC crashed while I was sending that last email. I have re-attached the document of yours that I discovered. Please read attached document and respond ASAP.
    Sincerely,
    User
  • Your email was sent in an INVALID format. To verify this email was sent from you, simply open the attached email (.eml) file and click yes in the sender options box.
    Thank You, User
  • Your email was received.
    YOUR REPLY IS URGENT!
    Please view the attached text file for instructions.
    Regards,
    User
  • I was in a hurry and I forgot to attach an important document. Please see attached.
    Best Regards, User
  • I resent this email as attachment because it was previously blocked by your email filters. Please read the attachment and respond.
    Thanks,User
  • Sorry, I forgot to attach the new contact information. Please view the attached (.pdf) contact sheet.
    Sincerely,
    User

Attachment: May be a ZIP archive or an EXE. If a ZIP attachment, one of the following filenames is used:

  • backup.zip
  • admin.zip
  • archivator.zip
  • about.zip
  • readme.zip
  • help.zip
  • photos.zip
  • payment.zip
  • archives.zip
  • manual.zip
  • inbox.zip
  • docs.zip
  • outbox.zip
  • save.zip
  • rar.zip
  • zip.zip
  • ataches.zip
  • documentation.zip

If an EXE, one of the following filenames is used:

  • backup.doc (many spaces) .exe
  • admin.doc (many spaces) .exe
  • archivator.doc (many spaces) .exe
  • about.doc (many spaces) .exe
  • readme.doc (many spaces) .exe
  • help.doc (many spaces) .exe
  • photos.doc (many spaces) .exe
  • payment.doc (many spaces) .exe
  • archives.doc (many spaces) .exe
  • manual.doc (many spaces) .exe
  • inbox.doc (many spaces) .exe
  • outbox.doc (many spaces) .exe
  • save.doc (many spaces) .exe
  • rar.doc (many spaces) .exe
  • zip.doc (many spaces) .exe
  • ataches.doc (many spaces) .exe
  • documentation.doc (many spaces) .exe
  • docs.doc (many spaces) .exe
  • sysboot.doc (many spaces) .exe

Overwriting of local hosts file

The local hosts file is overwritten, redirecting queries to any of the following remote servers to localhost (127.0.0.1):

  • www3.ca.com
  • www.viruslist.ru
  • www.trendmicro.com
  • www.symantec.com
  • www.networkassociates.com
  • www.nai.com
  • www.my-etrust.com
  • www.sophos.com
  • www.mcafee.com
  • www.kaspersky.ru
  • www.f-secure.com
  • www.fastclick.net
  • www.ca.com
  • www.awaps.net
  • www.avp.ru
  • www.avp.com
  • www.avp.ch
  • windowsupdate.microsoft.com
  • viruslist.ru
  • vil.nai.com
  • us.mcafee.com
  • updates.symantec.com
  • update.symantec.com
  • symantec.com
  • support.microsoft.com
  • spd.atdmt.com
  • sophos.com
  • service1.symantec.com
  • securityresponse.symantec.com
  • secure.nai.com
  • phx.corporate-ir.net
  • office.microsoft.com
  • networkassociates.com
  • nai.com
  • my-etrust.com
  • msdn.microsoft.com
  • media.fastclick.net
  • mcafee.com
  • mast.mcafee.com
  • liveupdate.symantec.com
  • go.microsoft.com
  • ftp.sophos.com
  • ftp.f-secure.com
  • f-secure.com
  • fastclick.net
  • engine.awaps.net
  • downloads.microsoft.com
  • download.microsoft.com
  • download.mcafee.com
  • dispatch.mcafee.com
  • clicks.atdmt.com
  • click.atdmt.com
  • ca.com
  • banners.fastclick.net
  • banner.fastclick.net
  • awaps.net
  • avp.ru
  • avp.com
  • avp.ch
  • atdmt.com
  • ar.atwola.com
  • ads.fastclick.net
  • ad.fastclick.net
  • ad.doubleclick.net

The hosts file is detected (and deleted) as W32/Bagz!hosts with the specified DATs.

Uninstallation of Security Products

The virus carries a large list of filenames which it uses in an attack against existing security products, terminating running processes, and deleting files and Registry keys associated with those products.

Removal -

Removal -

All Users:
Use specified engine and DAT files for detection and removal.

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A