Email-Worm.Win32.Bagle.ai

tag:E-mail   Worms  

0 0

This worm spreads via the Internet as an attachment to infected messages and also via P2P networks.

It is approximately 20 KB in size and packed using PEX.

Installation

Once launched, the worm copies itself to the Windows system directory as winxp.exe. It then registers this file in the system registry to ensure that this file is launched each time the system is started.

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "key"="%system%\winxp.exe"

The worm also creates the following files in the Windows system directory:

winxp.exeopen
winxp.exeopenopen
winxp.exeopenopenopen
winxp.exeopenopenopenopen

Propagation

The worm searches disks for files with extensions from the following lists. It sends itself to all addresses harvested from these files.

adb
asp
cfg
cgi
dbx
dhtm
eml
htm
jsp
mbx
mdx
mht
mmf
msg
nch
ods
oft
php
pl
sht
shtm
stm
tbb
txt
uin
wab
wsh
xls
xml

©Virus-Encyclopedia.com All Rights Reserved.