Read with Formatting | Join TechSpot! (it's free) | Bookmark / Share this



foto.zip carries Worm_Bagle.AI

Phantasm66
09-01-2004, 02:18 PM
There's been a recently spate of e-mails sent around, with the subject line of "foto" and carrying a file called foto.zip (http://www.pcmag.com/article2/0,1759,1641526,00.asp), which of course is malicious code. Its a zip file containing an HTML file, which when opened will drop downloader component on the victim's machine, which then attempts to connect to one of many web sites to download the worm portion. This new viruses has been named Worm_Bagle.AI (http://www.pcmag.com/article2/0,1759,1641526,00.asp). The web sites that carry the propagation code have fortunately been replete with problems, which have prevented infection from reaching the heights it could have. The virus is also known as Bagle.AV [Panda], Download.Ject.D [Symantec], W32/Bagle.dll.dr [McAfee], Troj/BagleDl-A [Sophos]. More on this here (http://www.anandtech.com/news/shownews.aspx?i=22867).

Godataloss
09-01-2004, 02:34 PM
I've already deleted 30 instances of this from my company's inbox today.

Ad
09-01-2004, 02:34 PM

Phantasm66
09-01-2004, 03:34 PM
I've had nothing, not in my Lotus notes at work, or my inbox at home.

EvilKernel
09-03-2004, 12:37 PM
We have antigen setup to remove htm attachments even within zip files, at the exchange level, so the user just gets a zip file with a text file inside which states Antigen removed the containing file.

You can't rely on deleting worms/virus by visiting user machines.

 Top Technology News

 Software Downloads

Copyright © 1998-2008 TechSpot.com. TechSpot is a registered trademark. All Rights Reserved.