PRESS RELEASE
Oslo, Norway, 26 March 2004

A new email worm in the Bagle family is spreading in rapidly growing numbers this morning, and has already been reported from many countries.  The worm has been named W32/Bagle.U.

It is spread as an attachment to emails with empty subject line and empty email body.  Few details are known, as analysis of the worm is just starting.

The detection rate among different antivirus products is initially very low, which increases the chance that users’ computers and networks may become infected.  Norman’s SandBox engine detects the worm without signature updates as ""Sandbox: W32/Backdoor".

For further information please look at http://www.norman.com/Virus/Virus_descriptions/14646 

Recommendations

Norman SandBox detects this worm. Please check for further information on Norman’s web when the worm is completely analyzed


Contact information

Steinar Wigtil, Director of R&D, Norman Data Defense Systems ASA,
Telephone +47 67 10 97 29, mobile phone +47 41 53 97 29

Audun Lødmel, Marketing, Norman Data Defense Systems ASA,
Telephone +47 67 10 97 79, mobile phone +47 93 44 65 31