Additional Details
Email-Worm:W32/Bagle.AT spreads via e-mail file attachments and through Peer-to-Peer (P2P) networks, as well as through a prepended Windows Control Panel Applet (CPL) stub.
This worm is programmed to cease its activity on Apr 25th, 2006.
Infection
Bagle.AT arrives a file attachment to an e-mail message, which has varying subject lines and body texts. The attachment is an executable file with one the following extensions: .EXE, .SCR, .COM and .CPL. The worm uses several different icons for the attachments it sends, such as these:
When the worm's file is run, it copies itself as wingo.exe to Windows System folder and creates a startup key for this file in the Registry:
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"wingo" = "%SystemDir%\ wingo.exe"
%SystemDir% represents the Windows System folder name, for example C:\Windows\System32 on Windows XP systems.
If system date is Apr 25th, 2006 the worm uninstalls itself from the infected system by deleting its startup key in the Registry and terminating its own process.
The worm creates 2 more files in Windows System folder:
- wingo.exeopen
- wingo.exeopenopen
These files are used when the worm spreads itself in e-mails.
To find new victims, Bagle.AT scans the hard drive to collect e-mail addresses. Files with the following extensions are checked: