This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Virus Removal Tools

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

More info on this from the Internet Storm Center:

- http://isc.sans.org/diary.html?date=2004-01-19
"…Reports to the ISC indicate that AV gateways intercepting this worm and configured to "Autoreply" to the spoofed "From:" source are once again causing needless congestion (see SOBIG issues). Offenders should consider changing this configuration. Three write-ups specify the worm's email will have an attachment "Length: 15,872 bytes" and one write-up says it is "an .exe file extension and consists of 3 - 11 randomly-generated lowercase characters." After infection and initiation of it's email routine AV write-ups state that Bagel "will initialize and open a TCP socket in listening mode on port 6777."…

One Vendor (TrendMicro) cryptically reports "This worm may perform port scanning to connect to a remote system."
- http://securityresponse.symantec.com/[removed]

- http://vil.nai.com/vil/content/v_100965.htm
- http://www3.ca.com/virusinfo/virus.aspx?ID=38019
- http://www.sophos.com/virusinfo/analyses/w32baglea.html
- http://www.f-prot.com/virusinfo/descriptions/bagle_a.html
- http://www.messagelabs.com/viruseye/threats/list/default.asp
- http://wtc.trendmicro.com/wtc/summary.asp