Computer Virus Alert

Socializing and general posts on wide-ranging topics. Remember, it's Poststructural!
Post Reply
User avatar
amar
Posts: 4857
Joined: Sat Feb 09, 2002 6:00 pm
antispam: No
Please enter the next number in sequence: 12
Location: Basel, Switzerland
Contact:

Computer Virus Alert

Post by amar »

Dear Trend Micro customer,

As of January 27, 2005 1:42 AM PST (Pacific Standard Time/GMT -8:00),
TrendLabs has declared a Medium Risk Virus Alert to control the spread
of WORM_BAGLE.AZ. TrendLabs has received several infection reports
indicating that this malware is spreading in US, China, and Japan.

This WORM_BAGLE variant arrives on a system as an email attachment. It
sends copies of itself to all email addresses it gathers from files
with certain extensions but skips those addresses that contain particular
strings.

===============================
Users must be wary of the email it sends that have the following
details:

Subject: (any of the following)
Delivery service mail
Delivery by mail
Registration is accepted
Is delivered mail
You are made active
Thanks for use of our software.
Before use read the help

Message body: (any of the following)
Delivery service mail
Delivery by mail
Registration is accepted
Is delivered mail
You are made active
Thanks for use of our software.
Before use read the help

Attachments: (any of the following file names)
guupd02.exe
Jol03.exe
siupd02.exe
upd02.exe
viupd02.exe
wsd01.exe
zupd02.exe

(with any of the following extensions)
COM
CPL
EXE
SCR
===============================

The email is spoofed and may appear to have come from a familiar email
address. As a general rule, users should avoid opening the attachments
of unsolicited email.

This worm drops a copy of itself using the following file names into
the Windows system folder:

sysformat.exe
sysformat.exeopen
sysformat.exeopenopen
It also looks for folders that have the string shar then drops copies
of itself using file names with EXE extensions into those folders.

In addition, this worm terminates several processes, most of which are
related to antivirus and security programs.

TrendLabs has uploaded the following:

TMCM Outbreak Prevention Policy 140
Official Pattern Release 2.375.00
Damage Cleanup Template 495




For more information on WORM_BAGLE.AZ, you can visit our Web site at:
http://www.trendmicro.com/vinfo/virusen ... M_BAGLE.AZ
Contact av_query@support.trendmicro.com for inquiries and to report
infections in your region.
Last edited by amar on Fri Jan 28, 2005 12:51 am, edited 1 time in total.
Image
Image
User avatar
Joseph E. Smith
Posts: 13780
Joined: Sat Mar 06, 2004 2:40 pm
antispam: No
Location: ... who cares?...
Contact:

Post by Joseph E. Smith »

Thanks for the heads up Amar!
Image
User avatar
peeplj
Posts: 9029
Joined: Mon Jan 21, 2002 6:00 pm
Please enter the next number in sequence: 1
Location: forever in the old hills of Arkansas
Contact:

Post by peeplj »

I had one of these arrive in my inbox, it made it past Norton AV, so do be careful.

--James
Jack
Posts: 15580
Joined: Sun Feb 09, 2003 6:00 pm
Please enter the next number in sequence: 1
Location: somewhere, over the rainbow, and Ergoville, USA

Post by Jack »

I don't understand it.
User avatar
Jerry Freeman
Posts: 6074
Joined: Mon Dec 30, 2002 6:00 pm
antispam: No
Please enter the next number in sequence: 8
Location: Now playing in Northeastern Connecticut
Contact:

Post by Jerry Freeman »

Thanks for the tip, Amar. (Why don't you change the title to something like, "Computer Virus Alert ..." so people will know it's important.)

I went to Symantec's website, and it appears that this virus is now in their current virus definitions, so I did a live update.
http://securityresponse.symantec.com/av ... ba@mm.html

Again, thanks for the tip.

Best wishes,
Jerry
User avatar
Unseen122
Posts: 3542
Joined: Tue May 04, 2004 7:21 pm
antispam: No
Please enter the next number in sequence: 8
Tell us something.: Of course I'm not a bot; I've been here for years... Apparently that isn't enough to pass muster though!
Location: Los Angeles, CA
Contact:

Post by Unseen122 »

Thanks for the warning. I never open this stuff but now I have a reason to be careful.
User avatar
feadogin
Posts: 1123
Joined: Tue Aug 06, 2002 6:00 pm
Please enter the next number in sequence: 1
Location: San Francisco Bay Area

Post by feadogin »

I got two emails with this virus this morning so watch out, all! (Don't worry, I did not open them).

Justine
<a href="http://lilypie.com"><img src="http://b2.lilypie.com/akpBm8.png" alt="Lilypie 2nd Birthday Ticker" border="0" /></a>
User avatar
Guitar Kat =^..^=
Posts: 37
Joined: Sun Jan 23, 2005 3:45 pm
Please enter the next number in sequence: 1
Location: Alberta, Canada
Contact:

Post by Guitar Kat =^..^= »

Nothing in Canada yet. I'll keep you posted. ;)

But, those worms sound really deadly... playing with your system files, etc. :boggle:
~~~~
Kat =^..^=
Post Reply