Protector Plus Download Antivirus
Home
Download Antivirus
Antivirus Products
Order Antivirus


Antivirus Software for Windows XP/2000/2003
Antivirus Software for Windows Me/98
Antivirus Software for Exchange 2000/2003
Antivirus Software for NetWare

W32/Bagle.AZ Worm

NameW32/Bagle.AZ Worm
AliasesW32/Bagle.az@MM, W32/Bagle-AZ, anti virus, antivirus, virus, worm, bagle
Discovered on 28th September, 2004

 Virus Information - W32/Bagle.AZ Worm:

W32/Bagle.AZ is an email worm. This worm is a variant of W32/Bagle.A. The worm will infect Windows systems. The worm spreads through email, shared network drives and KaZaA P2P software.

The infected email carries a spoofed 'From' address picked up randomly from the infected system.

The subject of the infected email will be any one of the following.

Re: Thank you!
Re: Thanks :)
Re: Hello
Re: Hi
Re:

The body of the infected email will be the any one of the following;

:))
:)

It carries any one of the following infected attachments;

Joke
price
Price


The extension of the attachment may be any one of the following;

.cpl
.com
.exe
.scr
.zip

Upon execution of the attachment, the worm copies itself as bawindo.exe in the Windows System folder. It drops bawindo.exeopen and bawindo.exeopenopen, which are copies of the worm.

It alters the windows registry at the following location to load itself during next startup;

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

It creates several mutex to ensure only one instance of the worm is running. It terminates some variants of W32/Netsky.

____--->>>>U<<<<--____
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-
_ _-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
'D'r'o'p'p'e'd'S'k'y'N'e't'

The worm attempts create copies of itself in any folder that contains the substring shar. The worm files will have the following file names:

XXX hardcore images.exe
Windows Sourcecode update.doc.exe
Windown Longhorn Beta Leak.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Serials.txt.exe
Porno, sex, oral, anal cool, awesome!!.exe
Porno pics arhive, xxx.exe
Porno Screensaver.scr
Opera 8 New!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Microsoft Office 2003 Crack, Working!.exe
Matrix 3 Revolution English Subtitles.exe
Kaspersky Antivirus 5.0
KAV 5.0
Ahead Nero 7.exe
Adobe Photoshop 9 full.exe
ACDSee 9.exe

The worm opens TCP port 81 and an UDP port on the infected computer.

To propagate itself, the worm scans the following extensions and collects the available email addresses from the infected system;

.xml, .xls, .wsh, .wab, .uin, .txt, .tbb, .stm, .shtm, .sht, .pl, .php, .oft, .ods, .nch, .msg, .mmf, .mht, .mdx, .mbx, .jsp, .htm, .eml, .dhtm, .dbx, .cgi, .cfg, .asp, .adb.

The worm also tries to terminate antivirus and security related software.

Anti virus for Windows Download Now!


Home Page Download Antivirus Antivirus Products Order Antivirus

Copyright © 2005 Proland Software.All rights reserved

antivirus software, anti virus software, anti virus, download antivirus, download anti virus, free antivirus, free anti virus, antivirus, download, free, windows, windows xp, xp, sp2, windows me, windows 2000, 98, 95, nt, me, 2003, netware, anti-virus, virus, worm, trojan, protector, plus, proland, virus software, spyware