[ news_security_news ] Bagle-EN Gets Cream Cheese: Dedicated SMTP Engine
John Stith Staff Writer
2006-02-10
Insider Reports RSS Feed
It seems Bagles are found at more places than the local deli. A new version of the mailing worm Bagle-en@MM uses its own SMTP engine to send itself to all your friends and relatives. Don't forget it also gets keys to the backdoor.
The eSecurity Planety blog posted information regarding the worm:
Upon execution, it creates a copy of itself into the windows system directory:
%Windir%%SYSDIR%regmaping.exe
The following 2 files are also dropped into the same windows system directory:
%WIndir%%SYSDIR%regmaping.exeopen
%WIndir%%SYSDIR%regmaping.exeopenopen
A third file named "WINRESW.EXE" is also dropped in the Windows folder. WINRESW.EXE is a downloader component and is detected as W32/Bagle.dq.
This worm adds the following values to the registry to auto start itself when windows starts:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun
"Regmonitor" = "%Windir%%SYSDIR%windspl.exe"
More information can be found at this McAfee page.
Although the worm does bite, its risk is assessed as low. Once again, keep your antivirus software update and you should be fine.
Add to | DiggThis| Yahoo My Web
About the Author:
John is a staff writer for SecurityProNews covering cyber security.
More news_security_news Articles
Insider Reports RSS Feed
|
|