Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 4 May 2006 13:38:34 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Bagle-IW is a worm for the Windows platform.
W32/Bagle-IW includes functionality to access the internet and communicate with a remote server via HTTP.
W32/Bagle-IW spreads via email. The attachment will have one of the following names:
Message
Document
README
Passwords
Readme
Important
Archive
private
confidential
secret
images
your_documents
backup
The Subject line of the email is selected at random from the following list:
Hi, what's up?
He, where are you?
Hi, drop me a line!!!
Hi! Please write to me urgently!
Hi! I'm waiting you online today!
Will you be online today?
When you're gonna answer me?
Re: write to me!
Re: Call me!
Re: Where are you?
Re: When you're gonna answer me?
Hi!!! How's the mood?
Re: How's the mood?
Re: Where have you been?
The message text will be randomly selected from one of the following blocks:
Hi!!!!! You haven't been writing for a long time. I began to worry) Where have you been? You remember, you've asked a progy from me? I've finally found it, so here it is. Check it out if this is what you've been looking for... bye
Hi, what's up? Will you show up online today?
Drop me a line in ICQ, ok? Btw, I'm sending you the docs you've been looking for, find them attached. Check them out, ok?
I'm coming to you tomorrow, ok? When you are going to be home?
You remember, you've asked some docs. Please find them attached. Check and see what's inside. That's it. Bye, till tomorrow...
You disappeared again. If you come online, drop me a line, ok?
Btw, I sent you those docs that you've been looking for. Check them out. Bye!
Hi, give me a call just when you got the message! I'm tired of waiting. Btw, I'm sending that program that you've been looking for. Check it out. Appears to be that one. Bye!
Hi, what's up? If you have time tomorrow, please come over. After midday. By the way, don't forget to check the enclosed documents. Bye. See you tomorrow.
Hi, I got a free day tomorrow, and I'm waiting for you. Please come after midday. By the way, I'm sending you the documents that you've been asking for. Read them out... Bye!
Hi, how are you? What are your plans today? If you have time, please come over, and don't forget to check the program attached. Bye!
Hi, what's you gonna do today? I'll come over tonight! By the way, don't give anyone this funny program I'm sending. Check it out. Bye!
Hi, I found that program you asked for. Find it attached. Bye.
Hi, I saw you around today, but you didn't noticed me ( If you're gonna be at home, give a call, ok? By the way, check this file I'm sending. A very interesting program...
What's up! You haven't been writing for a long time
I got news. I've finally that program you needed
I'm sending it out. Use it. Bye!
Hi, drop me a line today, ok? And see the program I'm sending. Bye!
Hi, drop me a line if you can. Btw, I have a new ICQ. Please don't forget to check the attached documents. Bye.
Hi! How are you? Drop me a line if you can. I found your documents and I'm emailing them to you. Bye.
W32/Bagle-IW is a worm for the Windows platform.
W32/Bagle-IW includes functionality to access the internet and communicate with a remote server via HTTP.
W32/Bagle-IW spreads via email. The attachment will have one of the following names:
Message
Document
README
Passwords
Readme
Important
Archive
private
confidential
secret
images
your_documents
backup
The Subject line of the email is selected at random from the following list:
Hi, what's up?
He, where are you?
Hi, drop me a line!!!
Hi! Please write to me urgently!
Hi! I'm waiting you online today!
Will you be online today?
When you're gonna answer me?
Re: write to me!
Re: Call me!
Re: Where are you?
Re: When you're gonna answer me?
Hi!!! How's the mood?
Re: How's the mood?
Re: Where have you been?
The message text will be randomly selected from one of the following blocks:
Hi!!!!! You haven't been writing for a long time. I began to worry) Where have you been? You remember, you've asked a progy from me? I've finally found it, so here it is. Check it out if this is what you've been looking for... bye
Hi, what's up? Will you show up online today?
Drop me a line in ICQ, ok? Btw, I'm sending you the docs you've been looking for, find them attached. Check them out, ok?
I'm coming to you tomorrow, ok? When you are going to be home?
You remember, you've asked some docs. Please find them attached. Check and see what's inside. That's it. Bye, till tomorrow...
You disappeared again. If you come online, drop me a line, ok?
Btw, I sent you those docs that you've been looking for. Check them out. Bye!
Hi, give me a call just when you got the message! I'm tired of waiting. Btw, I'm sending that program that you've been looking for. Check it out. Appears to be that one. Bye!
Hi, what's up? If you have time tomorrow, please come over. After midday. By the way, don't forget to check the enclosed documents. Bye. See you tomorrow.
Hi, I got a free day tomorrow, and I'm waiting for you. Please come after midday. By the way, I'm sending you the documents that you've been asking for. Read them out... Bye!
Hi, how are you? What are your plans today? If you have time, please come over, and don't forget to check the program attached. Bye!
Hi, what's you gonna do today? I'll come over tonight! By the way, don't give anyone this funny program I'm sending. Check it out. Bye!
Hi, I found that program you asked for. Find it attached. Bye.
Hi, I saw you around today, but you didn't noticed me ( If you're gonna be at home, give a call, ok? By the way, check this file I'm sending. A very interesting program...
What's up! You haven't been writing for a long time
I got news. I've finally that program you needed
I'm sending it out. Use it. Bye!
Hi, drop me a line today, ok? And see the program I'm sending. Bye!
Hi, drop me a line if you can. Btw, I have a new ICQ. Please don't forget to check the attached documents. Bye.
Hi! How are you? Drop me a line if you can. I found your documents and I'm emailing them to you. Bye.
When first run W32/Bagle-IW copies itself to <Windows>\csrss.exe and creates the file <Temp>\Message.zip.
The file Message.zp is detected as W32/Bagle-Zip.
The following registry entry is changed to run W32/Bagle-IW on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe
Debugger
<Windows>\csrss.exe

