On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dan Ilett
Posted on ZDNet News: Mar 1, 2005 11:53:00 PM

A new variant of Bagle is spreading rapidly, security companies have warned.

Rather than being a mass-mailing worm, BagleDl-L is a Trojan horse that damages security applications and attempts to connect with a number of Web sites. It has been sent via spam lists to millions of addresses in the past 12 hours, said security company McAfee, which has upgraded it to a "medium" risk.

The new variant could also have boosted overall Bagle traffic, which has increased five times in the past 24 hours, e-mail security vendor Postini said Tuesday.

The attempt to disable security protection could expose systems to a variety of threats. "Any Trojan horse which turns off your antivirus or firewall can open you up to further attack, even by very old viruses," Graham Cluley, senior technology consultant for antivirus company Sophos, said in a statement.

Unlike a mass-mailing worm, the Trojan does not self-propagate, but the security companies have highlighted it because a high number of e-mails containing it have been detected.

Although the Trojan horse doesn't spread itself, the code is similar to other variants of the Bagle worm, which is why Sophos marked it a descendent of that program, Cluley said in an interview.

According to Sophos antivirus company F-Secure, the Web sites that the new Bagle links to currently contain no malicious code. However, Trojan and worm writers have been known to add malicious code to a Web site after the initial attack has calmed down, said Craig Schmugar, a senior virus research manager for McAfee.

For this Trojan to work, a certain amount of naivete is required on the part of victims because the e-mails contain a ZIP-file attachment that must be opened to display the programs "doc_01.exe" or "prs_03.exe," which must be run manually to infect a computer.

"This Trojan horse is aiming to take advantage of people's reflex reaction when they receive an executable file via e-mail," Cluley said in a statement. "Users who want to install software on their computer should be receiving it from their IT department, not from friends at other companies or potentially dangerous spam mailings."

Variants of Bagle, which surfaced more than a year ago, continue to proliferate.

The detection of BagleDl-L comes just days after Send-Safe.com, which offered spamming tools, was kicked off Internet service provider MCI's network. Send-Safe is said to use PCs that have been compromised by Trojan horses to propagate spam.

Dan Ilett of ZDNet UK reported from London. CNET News.com's Dawn Kawamoto and Robert Lemos contributed to this report.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 103 Talkback(s)
Whatcha got Willis an Abrams MIA2
Dude if you have inetd enabled it can get hacked. If you want real security, switch to FreeBSD. OpenBSD is the most robust default install out of the box. FreeBSD is easier to setup on the i386.

By the way, FreeBSD has a superior file system.;)... (Read the rest)
Posted by: osreinstall Posted on: 03/03/05 You are currently: a Guest | | Terms of Use
Phew, I'm safe!  NonZealot | 03/01/05
You don't give yourself much credit....  James T. Kirk | 03/01/05
Hehe  NonZealot | 03/01/05
what it doesn't tell you  Monkey_MCSE | 03/01/05
Still...  James T. Kirk | 03/01/05
this is true  Monkey_MCSE | 03/01/05
No you're not  ITGuy04 | 03/01/05
Only in Windows?  NonZealot | 03/01/05
Yup. Rest are pretty much patched.  ITGuy04 | 03/01/05
Interesting  NonZealot | 03/01/05
BSD firewalls  RestonTechAlec | 03/01/05
Never under estimate a carbon life form  osreinstall | 03/01/05
I really don't think so  skeptic tank | 03/01/05
It was an analogy of things to come  osreinstall | 03/01/05
So true  voska | 03/01/05
If only everyone was that smart...  Linux_Developer | 03/01/05
I'm hopeful  NonZealot | 03/01/05
Admin as default  htotten | 03/02/05
Actually, XP Home asks with the OOBE...  The King's Servant | 03/02/05
administrative rights  cardinal33 | 03/01/05
wow, one willing to learn, kudos to you  Monkey_MCSE | 03/01/05
Windows Update and RunAs  Real World | 03/01/05
hmmm never ran into the problem  Monkey_MCSE | 03/01/05
permissions  Real World | 03/01/05
Same problem here, since XP SP2  PB_z | 03/01/05
correction to comment  Monkey_MCSE | 03/01/05
Ominous feeling.  Anton Philidor | 03/01/05
Please share the info?  flags2rus@... | 03/01/05
Here is some info  NonZealot | 03/01/05
I am safe fro now  Bio_nuclear | 03/02/05
Reason 1039494988585884 not to use Windows  ITGuy04 | 03/01/05
Reason 10394949885858845 we are glad you are not using Windows  Confused by religion | 03/01/05
I make my living fixinf this stuff  ITGuy04 | 03/01/05
if you have to "fix" this at all...  JoeMama_z | 03/01/05
dang  IT Scion | 03/01/05
Love the response  htotten | 03/02/05
Sometimes it is better to...  Dave Mount | 03/03/05
From the article  rapson | 03/01/05
This is a linux solution  osreinstall | 03/01/05
No, THIS is a linux solution  Mack DaNife | 03/01/05
Your analogy is moot in 90% userland  osreinstall | 03/01/05
Hold on there....  htotten | 03/02/05
Not Really  osreinstall | 03/03/05
Solution??  Stebre | 03/02/05
I knew  jdahs@... | 03/01/05
Yes  Mack DaNife | 03/01/05
i wouldnt say venomous...  jdahs@... | 03/01/05
If viruses bother you that much,  TechType | 03/02/05
Here is another solution  osreinstall | 03/01/05
Wow, your friends must be ticked.  Letophoro | 03/01/05
Your right  osreinstall | 03/01/05
Well I would open it..butt it would be pointed towards  Laff | 03/01/05
No - Outlook does NOT auto-open  Confused by religion | 03/01/05
Message has been deleted.  itanalyst | 03/01/05
This is a comment you choose to make public?  Anton Philidor | 03/01/05
I'm Surprised It Hasn't Been Deleted Yet  itanalyst | 03/01/05
Don't use Outlook on general principals  osreinstall | 03/01/05
I guess you really don't use email then.  htotten | 03/02/05
Outlook  doc_cotton | 03/02/05
I could have told you this Thursday...  esdrasf@... | 03/01/05
The "weakness" is the user in this case, not the OS  A C | 03/01/05
Yup  NonZealot | 03/01/05
Imagine a secure OS  voska | 03/01/05
What about Security Enhanced Linux?  Hugh Jass | 03/01/05
SELinux has great promise  NonZealot | 03/01/05
When you play - set SELinux to non-enforcing mode  Hugh Jass | 03/01/05
Thanks Hugh! (NT)  NonZealot | 03/01/05
I agree...except for the uninstall thing.  esdrasf@... | 03/01/05
I disagree  voska | 03/01/05
Couldn't have said that better myself...  Wolfie2K3 | 03/01/05
This is 1/2 a Windows problem  thutchins | 03/01/05
ignorence is the biggest security hole...  JoeMama_z | 03/01/05
EXACTLY!  Wolfie2K3 | 03/01/05
This is not even a 1/10 Windows Problem  djc1309@... | 03/01/05
Remember the password protected zip Bagle?  NonZealot | 03/01/05
This is 100% a windows problem  Richard Flude | 03/01/05
But...  Hugh Jass | 03/01/05
XP can do this, you just don't know how  NonZealot | 03/01/05
Beat me to it.  htotten | 03/02/05
Security  Real World | 03/02/05
And all of the sudden  michael-t | 03/01/05
not a problem for a properly admin'd system...  JoeMama_z | 03/01/05
The fact that this can even WORK these days is sad...  BitTwiddler | 03/01/05
I think  jdahs@... | 03/01/05
If they haven't learned by now...  Hugh Jass | 03/01/05
really...  jdahs@... | 03/01/05
Linux users don't worry about viruses  matrixdomain | 03/01/05
Inform us  NonZealot | 03/01/05
Linux is Immune to viruses  matrixdomain | 03/01/05
Oh dear  NonZealot | 03/01/05
There are things Linux users should watch out for, though  Hugh Jass | 03/01/05
this case is about a totally outdated and ignored system  matrixdomain | 03/01/05
so what your saying is...  jdahs@... | 03/01/05
Probably..  Wolfie2K3 | 03/02/05
Linux is more than 60% of internet web severs  matrixdomain | 03/02/05
So?  NonZealot | 03/02/05
Whatcha got Willis an Abrams MIA2  osreinstall | 03/03/05
Actually  RichardM_z | 03/02/05
Windows security  Real World | 03/02/05
Well said!  jan5055@... | 03/02/05
Innacurate post  NonZealot | 03/02/05
Linux vs. Windows  jan5055@... | 03/02/05
Tired of the Flame wars.  xshakes | 03/02/05

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here