www.whizpr.nlwww.marcommit.nlProgressCommunications.eu
INFLUX PRwww.deepr.nlwww.deepr.nl

x.com/ictberichten
Datum: (22 jaar en 81 dagen geleden)
Bedrijf:
PR: Progress Communications

Kaspersky Lab Virus News: A new version of the Internet worm Bagle causes a global epidemic

Kaspersky Labs has detected I-Worm.Bagle.b, a new modification of the notorious Internet worm Bagle. To date, several hundred users throughout the world have sent notification of messages infected by the worm.

A conservative estimate of the number of infected messages in global mail traffic would be over 20000, and the number is steadily rising. This indicates that the worm is significantly less widespread than the infamous Mydoom.a. However, prior to the appearance of Mydoom.a, the most widespread worm of 2004 was Bagle.a, the previous version of the current worm.

The new version of I-Worm.Bagle is similar to its predecessor in many ways. The malicious program spreads via email as an infected file attached to messages. The worm is an executable Windows file of approximately 11KB. The message header reads "ID x...thanks" and the message body reads "Yours ID x...Thank", with x in both cases being a random string of characters.

Once launched, the worm copies itself to the Windows system directory and registers itself in the system registry auto-run key. In order to confuse the user, the worm also launches Sound Recorder (sndrec32.exe), a standard Windows utility. Following this, Bagle.b attempts to establish a connection with a number of remote sites which are in some way connected with the Trojan proxy server TrojanProxy.Win32.Mitglieder. At the moment, all links to Internet resources where Mitglieder can be downloaded have been deleted, which means that I-Worm.Bagle is unable to utilitize this method to increase the speed at which it propagates.

However, the most dangerous threat to infected computers is the Trojan component in the body of the worm. This opens port 8866 on the victim computer, and then monitors port activity. Consequently, the  computer is then open for the author of the worm to execute commands or download files to the victim machine.

Just like its predecessor, I-Worm.Bagle.b uses a procedure standard for this type of malicious code to propagate. It scans the file system of the victim computer for files with the extensions wab, txt, htm, html and r1, and then sends itself to all email addresses found in these files.  The worm uses its own SMTP server to send messages. The activity of this particular malicious program is time-limited, as the worm is programmed to cease propagating after 25th February 2004. This may be a sign that a new version of Bagle is being written, which will appear after the date shown above.

Protection against I-Worm.Bagle.b has already been added to Kaspersky Anti-Virus databases. A more detailed description can be found in the Virus Encyclopaedia.

For more information contact our local office:

Kaspersky Lab Benelux BV
Havensingel 1a
5211 TX 's-Hertogenbosch
Press Contact: Dick Gehéniau
(t) 073 6154860
info@kasperskylab.nl

Recent van Kaspersky  
Kaspersky onderzoek: de werking van AI-gedreven ransomewaregroep FunkSec

Verstreken tijd: 22 jaar en 81 dagen
PR contact  

Logo Progress Communications
Kaspersky contact  


Marcommit is hét full service B2B marketing bureau van Nederland! Wij helpen jouw bedrijf met offline en online marketing campagnes die écht werken.
 Spotlight  
Logo Decos
Logo Companial
Logo Companial
Logo 12Build
Logo Key2XS
Logo Frontline Solutions
Logo Delta-N B.V.
Logo R-Go Tools B.V.
Logo Blastic
Logo Key2XS
Logo BusinessCom
Logo NetBoss B.V.
Logo Cyemptive
Logo RawWorks B.V.
Logo Drukbedrijf
Logo BusinessCom
Logo SCOS ViaCloud BV
Logo Web Wings
Logo Frontline Solutions
Logo Keuze.nl BV
Logo We talk SEO B.V.
Logo We talk SEO B.V.
Logo We talk SEO B.V.
Logo Data Tribes
Logo MCS B.V.
Logo Onventis B.V.
Logo Web Wings
Logo Msafe
Logo Onventis B.V.
Logo Networking4ALL
Logo Palo Alto Networks
Logo Schneider Electric
Logo Xebia
Logo Trend Micro
Logo Veeam Software
Logo Descartes
Logo Huawei Technologies (Netherlands) B.V.
Logo Amazon Web Services
Logo Furore Conclusion
Logo Zscaler
Logo Anker Innovations
Logo Vertiv
Logo Wuunder
Logo Graduate Ventures
Logo HeadFirst Group
TARIEVEN
Publicatie eenmalig €49

PUBLICATIEBUNDELS
6 voor €199
12 voor €349
Onbeperkt €499

EENMALIG PLAATSEN
Persbericht aanleveren

REGELMATIG PLAATSEN
Bedrijfsabonnement
CONTACT
Persberichten.com
JMInternet
Kuyperstraat 48
7942 BR Meppel
Nederland
info@persberichten.com
KvK 54178096

VOLGEN
@ICTBERICHTEN

ZOEKEN
IT bedrijf
IT PR-bureau
OVER ONS
Persberichten.com, hét platform voor IT/Tech persberichten

DATABASE
103478 persberichten
7019 bedrijfsprofielen
59 PR-bureauprofielen
17287 tags

KENMERKEN
• Behouden tekstopmaak
• Foto/illustratie/logo
• Downloadbare bijlages
• Profiel met socials
 
www.whizpr.nlwww.marcommit.nlProgressCommunications.eu
ProgressCommunications.euINFLUX PRINFLUX PR