also @ TechSpot: Nortel's internal network "owned" by hackers for almost a decade
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > TechSpot Community > General Discussion

Collaborate in the cloud with Office, Exchange, SharePoint, and Lync

foto.zip carries Worm_Bagle.AI

Thread Tools Search this Thread
  #1  
Old 09-01-2004
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
foto.zip carries Worm_Bagle.AI

There's been a recently spate of e-mails sent around, with the subject line of "foto" and carrying a file called foto.zip, which of course is malicious code. Its a zip file containing an HTML file, which when opened will drop downloader component on the victim's machine, which then attempts to connect to one of many web sites to download the worm portion. This new viruses has been named Worm_Bagle.AI. The web sites that carry the propagation code have fortunately been replete with problems, which have prevented infection from reaching the heights it could have. The virus is also known as Bagle.AV [Panda], Download.Ject.D [Symantec], W32/Bagle.dll.dr [McAfee], Troj/BagleDl-A [Sophos]. More on this here.
  #2  
Old 09-01-2004
Godataloss's Avatar
TechSpot Booster
 
Location: Lorain, Ohio
Member since: Oct 2003, 501 posts
I've already deleted 30 instances of this from my company's inbox today.
  #3  
Old 09-01-2004
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
I've had nothing, not in my Lotus notes at work, or my inbox at home.
  #4  
Old 09-03-2004
Banned
 
Member since: May 2004, 36 posts
We have antigen setup to remove htm attachments even within zip files, at the exchange level, so the user just gets a zip file with a text file inside which states Antigen removed the containing file.

You can't rely on deleting worms/virus by visiting user machines.
Closed Thread

Similar Topics
Topic Replies Forum
BestBuy.Com now carries Alienware PC's? 11 General Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 05:03 AM.