Bagle.AH, Worm Is Spreading Worldwide

    July 21, 2004

Panda Software has detected the appearance of the new worm Bagle.AH (W32/Bagle.AH.worm), a malicious code that uses both email and file-sharing programs like Kazaa, Morpheus, e-mule or LimeWire in order to spread rapidly across computers.

According to Panda the Bagle.AH worm uses an email with a false address to spread. The message text includes words like: “Predators”, “Lovely animals”, “fotoinfo”, “The snake” or “Animals”.

To spread to other email addresses, it has an attachment that must be run for the infection to start. This file could be called: “Serials.txt.exe”, “Porno Screensaver.scr”, “Microsoft Office 2003 Crack, Working!.exe”, or “”. The file could sometimes be included in a password protected ZIP file.

When the file containing the Bagle.AH worm is run, it starts to look on the infected computer for addresses to which it then sends itself.

This worm also uses P2P file-sharing programs in order to spread. To do this it makes a copy of itself in the shared directories of these applications with names that could entice other users to download and run them.

The damaging effects that this worm can have on computers include the blocking of antivirus or security application processes in memory which could leave computers vulnerable to further attack.

At the same time as the appearance of Bagle.AH, two new versions of Mydoom and Lovgate have started to spread across the Internet. W32/Mydoom.M.worm and W32/Lovgate.AQ.worm infected some computers and although initially it was feared that the epidemic could spread due to the simultaneous action of the worms, only Bagle.AH has become a real threat to a large number of computers.

Due to the risk of being infected by Bagle.AH, Panda Software advises users to stay on their guard and make sure their antivirus is updated. The company has already made the updates to its products available to its clients to ensure their solutions can detect and eliminate Bagle.AH.

Users can also scan and disinfect their computers using Panda ActiveScan, the free, online scanner available from Panda Software.