Content
W32/Bagz.d@MM
- Type
- Virus
- SubType
- E-mail worm
- Discovery Date
- 10/19/2004
- Length
- 157,186 bytes (EXE)
153,007 bytes (ZIP) - Minimum DAT
- 4400 (10/20/2004)
- Updated DAT
- 5791 (11/03/2009)
- Minimum Engine
- 5.1.00
- Description Added
- 10/19/2004
- Description Modified
- 10/19/2004 10:52 AM (PT)
Tab Navigation
Characteristics
This variant of W32/Bagz@MM is similar to previous variants (for example W32/Bagz.b@MM ), bearing the following characteristics:
- it is packed with UPX
- consists of multiple file components
- constructs messages using its own SMTP engine, attaching itself as an EXE (sometimes within a ZIP archive)
- disables/uninstalls certain security/AV products from the victim machine
- overwrites the local hosts file (to prevent certain products from updating correctly)
Symptoms
- Local hosts file overwritten as described below
- Outgoing messages matching these characteristics
The worm drops the following files when executed:
- %WinDir%\SYSTEM32\RPC32.EXE (123,904 bytes)
- %WinDir%\SYSTEM32\RUN32.EXE (9,728 bytes)
- %WinDir%\SYSTEM32\SYSBOOT.DOC (many spaces) .EXE (157,187 bytes)
The RPC32.EXE file is installed as service on the victim machine, with the following properties:
Display Name:
Network Explorer
Image Path:
%WinDir%\SYSTEM32\RPC32.EXE
Description:
Starts and configures accessibility tools from one window
The service is installed to start automatically at system startup.
Note: The 9,728 byte component (RUN32.EXE) is detected as W32/Bagz!proxy since the 4397 DATs.
Method of Infection
Mail Propagation
The virus harvests target email addresses from the victim machine, from the following filetypes:
- .TBB
- .tbb
- .TBI
- .tbi
- .DBX
- .dbx
- .HTM
- .htm
- .TXT
- .txt
Email addresses containing any of the following strings will not be targetted:
- winzip
- winrar
- webmaster@
- update
- unix
- support@
- support
- spam
- sopho
- samples
- root@
- rating@
- postmaster@
- pgp
- panda
- ntivi
- noreply
- noone@
- nobody@
- news
- netadmin@
- local
- listserv
- linux
- kasp
- info@
- icrosoft
- hostmaster@
- help@
- gold-certs@
- gold-
- free-av
- feste
- f-secur
- contract@
- contact@
- certs@
- certific
- cafee
- bugs@
- bsd
- anyone@
- all@
- administrator@
- admin
- abuse
- @microsoft
- @messagelab
- @iana
- @foo
- @avp
- oocies
Outgoing messages are constructed as follows:
Subject: Any of the following:
- ASAP
- please responce
- Read this
- urgent
- toxic
- contract
- Money
- office
- Have a nice day
- Hello
- Russian's
- Amirecans
- attachments
- attach
- waiting
- best regards
- Administrator
- Warning
- text
- Vasia
- re: Andrey
- re: please
- re: order
- Allert!
- Att
Message Body: Uses one of the following message bodies.
- Did you get the previous document I attached for you? I resent it in this email just in case, because I really need you to check it out asap.
Best Regards - I made a mistake and forgot to click attach on the previous email I sent you. Please give me your opinion on this opportunity when you get a chance.
Best Regards - I was supposed to send you this document yesterday. Sorry for the delay, please forward this to your family if possible. It contains important info for both of you.
- Sorry, I forgot to send an important document to you in that last email. I had an important phone call. Please checkout attached doc file when you have a moment.
Best Regards - I was in a rush and I forgot to attach an important document. Please see attached doc file.
Best Regards, - I am responding to your last email in the attached file. Please get back to me if there is any problem reading the attachment.
- I had a delivery problem with your inbox, so maybe you'll receive this now. For some reason, I received only part of your last several emails. I want to make sure that there are no problems with either of our accounts. it was previously blocked by your email filters.
Please view the attachment and respond.
Thanks - it was previously blocked by your email filters. Please read the attachment and respond.
Thanks - My system crashed last weekend and I lost most of my friends and work contacts. Please check the attached (.pdf) and please let me know if your info is current.
- The reason is that I am not currently added to your "allowed" contact list. Please add my updated contact info provided in the attached (.pdf) file so I can send you emails in the future.
Sincerely - See the (.pdf) file attached and please respond if you have any questions.
- Please verify your mailing address on file is correct. We have attached a (.pdf) sheet for you to use for your response.
- Our contact information has changed. See the attached (.pdf) sheet for details.
Sincerely, - Due to your failure to comply with our email Rules and Regulations, your email account has been temporarily suspended for 24 hours unless we are contacted regarding this situation. You must read the attached document for further instructions. Failure to comply will result in termination of your account.
Regards,
Net Operator - ***URGENT: SERVICE SHUTDOWN NOTICE***
You are currently unable to send emails. This may be a billing issue. Please call the billing center. The # for the billing office is located in the attached contact list for your convenience. - ***ATTENTION: YOUR EMAIL IS NOT BEING DELIVERED!***
Hello,
The previous email you sent has been recognized as spam. This means your email was not delivered to your friend or client. You must open the attached file to receive more information. - ***YOUR MESSAGE HAS BEEN RECOGNIZED AS SPAM***
What version of windows you are using? This last document I received from you came out weird. Please see the attached word file and resend the file to me.
Many thanks,
User - My PC crashed while I was sending that last email. I have re-attached the document of yours that I discovered. Please read attached document and respond ASAP.
Sincerely,
User - Your email was sent in an INVALID format. To verify this email was sent from you, simply open the attached email (.eml) file and click yes in the sender options box.
Thank You, User - Your email was received.
YOUR REPLY IS URGENT!
Please view the attached text file for instructions.
Regards,
User - I was in a hurry and I forgot to attach an important document. Please see attached.
Best Regards, User - I resent this email as attachment because it was previously blocked by your email filters. Please read the attachment and respond.
Thanks,User - Sorry, I forgot to attach the new contact information. Please view the attached (.pdf) contact sheet.
Sincerely,
User
Attachment: May be a ZIP archive or an EXE. If a ZIP attachment, one of the following filenames is used:
- backup.zip
- admin.zip
- archivator.zip
- about.zip
- readme.zip
- help.zip
- photos.zip
- payment.zip
- archives.zip
- manual.zip
- inbox.zip
- docs.zip
- outbox.zip
- save.zip
- rar.zip
- zip.zip
- ataches.zip
- documentation.zip
If an EXE, one of the following filenames is used:
- backup.doc (many spaces) .exe
- admin.doc (many spaces) .exe
- archivator.doc (many spaces) .exe
- about.doc (many spaces) .exe
- readme.doc (many spaces) .exe
- help.doc (many spaces) .exe
- photos.doc (many spaces) .exe
- payment.doc (many spaces) .exe
- archives.doc (many spaces) .exe
- manual.doc (many spaces) .exe
- inbox.doc (many spaces) .exe
- outbox.doc (many spaces) .exe
- save.doc (many spaces) .exe
- rar.doc (many spaces) .exe
- zip.doc (many spaces) .exe
- ataches.doc (many spaces) .exe
- documentation.doc (many spaces) .exe
- docs.doc (many spaces) .exe
- sysboot.doc (many spaces) .exe
Overwriting of local hosts file
The local hosts file is overwritten, redirecting queries to any of the following remote servers to localhost (127.0.0.1):
- www3.ca.com
- www.viruslist.ru
- www.trendmicro.com
- www.symantec.com
- www.networkassociates.com
- www.nai.com
- www.my-etrust.com
- www.sophos.com
- www.mcafee.com
- www.kaspersky.ru
- www.f-secure.com
- www.fastclick.net
- www.ca.com
- www.awaps.net
- www.avp.ru
- www.avp.com
- www.avp.ch
- windowsupdate.microsoft.com
- viruslist.ru
- vil.nai.com
- us.mcafee.com
- updates.symantec.com
- update.symantec.com
- symantec.com
- support.microsoft.com
- spd.atdmt.com
- sophos.com
- service1.symantec.com
- securityresponse.symantec.com
- secure.nai.com
- phx.corporate-ir.net
- office.microsoft.com
- networkassociates.com
- nai.com
- my-etrust.com
- msdn.microsoft.com
- media.fastclick.net
- mcafee.com
- mast.mcafee.com
- liveupdate.symantec.com
- go.microsoft.com
- ftp.sophos.com
- ftp.f-secure.com
- f-secure.com
- fastclick.net
- engine.awaps.net
- downloads.microsoft.com
- download.microsoft.com
- download.mcafee.com
- dispatch.mcafee.com
- clicks.atdmt.com
- click.atdmt.com
- ca.com
- banners.fastclick.net
- banner.fastclick.net
- awaps.net
- avp.ru
- avp.com
- avp.ch
- atdmt.com
- ar.atwola.com
- ads.fastclick.net
- ad.fastclick.net
- ad.doubleclick.net
The hosts file is detected (and deleted) as W32/Bagz!hosts with the specified DATs.
Uninstallation of Security Products
The virus carries a large list of filenames which it uses in an attack against existing security products, terminating running processes, and deleting files and Registry keys associated with those products.
Removal
All Users:
Use specified engine and DAT files for detection and removal.
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Characteristics
Characteristics -
This variant of W32/Bagz@MM is similar to previous variants (for example W32/Bagz.b@MM ), bearing the following characteristics:
- it is packed with UPX
- consists of multiple file components
- constructs messages using its own SMTP engine, attaching itself as an EXE (sometimes within a ZIP archive)
- disables/uninstalls certain security/AV products from the victim machine
- overwrites the local hosts file (to prevent certain products from updating correctly)
Symptoms
Symptoms -
- Local hosts file overwritten as described below
- Outgoing messages matching these characteristics
The worm drops the following files when executed:
- %WinDir%\SYSTEM32\RPC32.EXE (123,904 bytes)
- %WinDir%\SYSTEM32\RUN32.EXE (9,728 bytes)
- %WinDir%\SYSTEM32\SYSBOOT.DOC (many spaces) .EXE (157,187 bytes)
The RPC32.EXE file is installed as service on the victim machine, with the following properties:
Display Name:
Network Explorer
Image Path:
%WinDir%\SYSTEM32\RPC32.EXE
Description:
Starts and configures accessibility tools from one window
The service is installed to start automatically at system startup.
Note: The 9,728 byte component (RUN32.EXE) is detected as W32/Bagz!proxy since the 4397 DATs.
Method of Infection
Method of Infection -
Mail Propagation
The virus harvests target email addresses from the victim machine, from the following filetypes:
- .TBB
- .tbb
- .TBI
- .tbi
- .DBX
- .dbx
- .HTM
- .htm
- .TXT
- .txt
Email addresses containing any of the following strings will not be targetted:
- winzip
- winrar
- webmaster@
- update
- unix
- support@
- support
- spam
- sopho
- samples
- root@
- rating@
- postmaster@
- pgp
- panda
- ntivi
- noreply
- noone@
- nobody@
- news
- netadmin@
- local
- listserv
- linux
- kasp
- info@
- icrosoft
- hostmaster@
- help@
- gold-certs@
- gold-
- free-av
- feste
- f-secur
- contract@
- contact@
- certs@
- certific
- cafee
- bugs@
- bsd
- anyone@
- all@
- administrator@
- admin
- abuse
- @microsoft
- @messagelab
- @iana
- @foo
- @avp
- oocies
Outgoing messages are constructed as follows:
Subject: Any of the following:
- ASAP
- please responce
- Read this
- urgent
- toxic
- contract
- Money
- office
- Have a nice day
- Hello
- Russian's
- Amirecans
- attachments
- attach
- waiting
- best regards
- Administrator
- Warning
- text
- Vasia
- re: Andrey
- re: please
- re: order
- Allert!
- Att
Message Body: Uses one of the following message bodies.
- Did you get the previous document I attached for you? I resent it in this email just in case, because I really need you to check it out asap.
Best Regards - I made a mistake and forgot to click attach on the previous email I sent you. Please give me your opinion on this opportunity when you get a chance.
Best Regards - I was supposed to send you this document yesterday. Sorry for the delay, please forward this to your family if possible. It contains important info for both of you.
- Sorry, I forgot to send an important document to you in that last email. I had an important phone call. Please checkout attached doc file when you have a moment.
Best Regards - I was in a rush and I forgot to attach an important document. Please see attached doc file.
Best Regards, - I am responding to your last email in the attached file. Please get back to me if there is any problem reading the attachment.
- I had a delivery problem with your inbox, so maybe you'll receive this now. For some reason, I received only part of your last several emails. I want to make sure that there are no problems with either of our accounts. it was previously blocked by your email filters.
Please view the attachment and respond.
Thanks - it was previously blocked by your email filters. Please read the attachment and respond.
Thanks - My system crashed last weekend and I lost most of my friends and work contacts. Please check the attached (.pdf) and please let me know if your info is current.
- The reason is that I am not currently added to your "allowed" contact list. Please add my updated contact info provided in the attached (.pdf) file so I can send you emails in the future.
Sincerely - See the (.pdf) file attached and please respond if you have any questions.
- Please verify your mailing address on file is correct. We have attached a (.pdf) sheet for you to use for your response.
- Our contact information has changed. See the attached (.pdf) sheet for details.
Sincerely, - Due to your failure to comply with our email Rules and Regulations, your email account has been temporarily suspended for 24 hours unless we are contacted regarding this situation. You must read the attached document for further instructions. Failure to comply will result in termination of your account.
Regards,
Net Operator - ***URGENT: SERVICE SHUTDOWN NOTICE***
You are currently unable to send emails. This may be a billing issue. Please call the billing center. The # for the billing office is located in the attached contact list for your convenience. - ***ATTENTION: YOUR EMAIL IS NOT BEING DELIVERED!***
Hello,
The previous email you sent has been recognized as spam. This means your email was not delivered to your friend or client. You must open the attached file to receive more information. - ***YOUR MESSAGE HAS BEEN RECOGNIZED AS SPAM***
What version of windows you are using? This last document I received from you came out weird. Please see the attached word file and resend the file to me.
Many thanks,
User - My PC crashed while I was sending that last email. I have re-attached the document of yours that I discovered. Please read attached document and respond ASAP.
Sincerely,
User - Your email was sent in an INVALID format. To verify this email was sent from you, simply open the attached email (.eml) file and click yes in the sender options box.
Thank You, User - Your email was received.
YOUR REPLY IS URGENT!
Please view the attached text file for instructions.
Regards,
User - I was in a hurry and I forgot to attach an important document. Please see attached.
Best Regards, User - I resent this email as attachment because it was previously blocked by your email filters. Please read the attachment and respond.
Thanks,User - Sorry, I forgot to attach the new contact information. Please view the attached (.pdf) contact sheet.
Sincerely,
User
Attachment: May be a ZIP archive or an EXE. If a ZIP attachment, one of the following filenames is used:
- backup.zip
- admin.zip
- archivator.zip
- about.zip
- readme.zip
- help.zip
- photos.zip
- payment.zip
- archives.zip
- manual.zip
- inbox.zip
- docs.zip
- outbox.zip
- save.zip
- rar.zip
- zip.zip
- ataches.zip
- documentation.zip
If an EXE, one of the following filenames is used:
- backup.doc (many spaces) .exe
- admin.doc (many spaces) .exe
- archivator.doc (many spaces) .exe
- about.doc (many spaces) .exe
- readme.doc (many spaces) .exe
- help.doc (many spaces) .exe
- photos.doc (many spaces) .exe
- payment.doc (many spaces) .exe
- archives.doc (many spaces) .exe
- manual.doc (many spaces) .exe
- inbox.doc (many spaces) .exe
- outbox.doc (many spaces) .exe
- save.doc (many spaces) .exe
- rar.doc (many spaces) .exe
- zip.doc (many spaces) .exe
- ataches.doc (many spaces) .exe
- documentation.doc (many spaces) .exe
- docs.doc (many spaces) .exe
- sysboot.doc (many spaces) .exe
Overwriting of local hosts file
The local hosts file is overwritten, redirecting queries to any of the following remote servers to localhost (127.0.0.1):
- www3.ca.com
- www.viruslist.ru
- www.trendmicro.com
- www.symantec.com
- www.networkassociates.com
- www.nai.com
- www.my-etrust.com
- www.sophos.com
- www.mcafee.com
- www.kaspersky.ru
- www.f-secure.com
- www.fastclick.net
- www.ca.com
- www.awaps.net
- www.avp.ru
- www.avp.com
- www.avp.ch
- windowsupdate.microsoft.com
- viruslist.ru
- vil.nai.com
- us.mcafee.com
- updates.symantec.com
- update.symantec.com
- symantec.com
- support.microsoft.com
- spd.atdmt.com
- sophos.com
- service1.symantec.com
- securityresponse.symantec.com
- secure.nai.com
- phx.corporate-ir.net
- office.microsoft.com
- networkassociates.com
- nai.com
- my-etrust.com
- msdn.microsoft.com
- media.fastclick.net
- mcafee.com
- mast.mcafee.com
- liveupdate.symantec.com
- go.microsoft.com
- ftp.sophos.com
- ftp.f-secure.com
- f-secure.com
- fastclick.net
- engine.awaps.net
- downloads.microsoft.com
- download.microsoft.com
- download.mcafee.com
- dispatch.mcafee.com
- clicks.atdmt.com
- click.atdmt.com
- ca.com
- banners.fastclick.net
- banner.fastclick.net
- awaps.net
- avp.ru
- avp.com
- avp.ch
- atdmt.com
- ar.atwola.com
- ads.fastclick.net
- ad.fastclick.net
- ad.doubleclick.net
The hosts file is detected (and deleted) as W32/Bagz!hosts with the specified DATs.
Uninstallation of Security Products
The virus carries a large list of filenames which it uses in an attack against existing security products, terminating running processes, and deleting files and Registry keys associated with those products.
Removal -
Removal -
All Users:
Use specified engine and DAT files for detection and removal.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A