Proactive IT security
 Home  News  Products & services  Virus & security  Support  Download  Partner  Purchase
Select country
Select product
W32/Bagle.R@mm Destructivity: Low Spreading: Medium Overall risk: Medium
Detected by virus detection files published: 18. Mar 2004
Virus characteristics first published: 18 Mar. 2004
Virus characteristics latest update: 07 May. 2004
Type: Virus, Worm
Spreading mechanism: Email, File Infection, Other
Overall risk: Medium
Type Spreading mechanism Destructivity & payload Additional descriptions Detection & removal

The following is a portion of the instant analysis done by the Norman Sandbox Technology:

 [ General information ]
    * Attemps to open C:\WINDOWS\SYSTEM\direct.exe NULL.
    * Creating several executable files on hard-drive.
    * File length:        25600 bytes.
    * Total emulation cycles required:      4540790.

 [ Changes to filesystem ]
    * Creates file C:\WINDOWS\SYSTEM\direct.exe.

 [ Changes to registry ]
    * Deletes value "My AV" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "My AV" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "Zone Labs Client Ex" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "Zone Labs Client Ex" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "9XHtProtect" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "9XHtProtect" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "Antivirus" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "Antivirus" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "Special Firewall Service" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "Special Firewall Service" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "service" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "service" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "Tiny AV" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "Tiny AV" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "ICQNet" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "ICQNet" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "HtProtect" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "HtProtect" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "NetDy" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "NetDy" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "ICQ Net" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
    * Deletes value "ICQ Net" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
    * Creates value "direct.exe"="C:\WINDOWS\SYSTEM\direct.exe" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".

 [ Network services ]
    * Connect port 81 [DGRAM], IP 0.0.0.0.
    * Connect port 2556 [DGRAM], IP 0.0.0.0.

 [ Security issues ]
    * Possible backdoor functionality [UNKNOWN] port 81.
    * Possible backdoor functionality [UNKNOWN] port 2556.

 

 Write-up by Trygve Brox  

 

CURRENT VIRUS THREATS
Medium risk
24 Oct 07 Pidief.A
24 Jan 07 Tibs
25 Sep 06 Stration
18 Jan 06 Small.KI
12 Sep 05 Bagle.CS
17 Aug 05 Zotob.B
08 Jun 05 Mytob
17 Feb 05 MyDoom.AQ
26 Jul 04 MyDoom.L
25 Mar 04 Netsky.P
Low risk
05 Mar 07 Viking.GT
27 Jan 06 Feebs
16 Jan 05 MyDoom.AH
22 Apr 04 SDBot
30 Mar 04 Netsky.Q
Latest virus definition file published
2008-05-09
Norman is one of the world’s leading companies within the field of data security. With products for antivirus (virus control), personal firewall, antispam, and encryption, the company plays an important role in the data industry.