F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : Bagle.G

[Summary] | [Disinfection] | [Detection]



NAME:Bagle.G
ALIAS:W32/Bagle.G, W32/Bagle.G@mm

Summary

The Bagle.G variant is almost identical to Bagle.F variant. The difference is in one extra byte added to a text string that resulted in shifting of offsets in the worm's code.

The description of Bagle.F worm can be found here:

http://www.f-secure.com/v-descs/bagle_f.shtml

Disinfection

F-Secure provides the special disinfection utility to eliminate Bagle.G worm infection. You can download this utility from our ftp site:

ftp://ftp.f-secure.com/anti-virus/tools/f-bagle.exe

ftp://ftp.f-secure.com/anti-virus/tools/f-bagle.zip

Disinfection instructions can be found here:

ftp://ftp.f-secure.com/anti-virus/tools/f-bagle.txt

System administrators who are using F-Secure Policy Manager, can distribute the tool as a JAR package automatically to all workstations.

System administrators can download the JAR version from:

http://www.europe.f-secure.com/tools/f-bagle.jar

ftp://ftp.europe.f-secure.com/anti-virus/tools/f-bagle.jar

Back to the Top


Detection

Detection for Bagle.G worm was added in the following F-Secure Anti-Virus update:

[FSAV_Database_Version]

Version=2004-03-02_02


Back to the Top


Writeup: Alexey Podrezov, March 3rd, 2004;

Description Updated: Alexey Podrezov, March 22nd, 2004;

F-Secure Corporation