W32/Bagle.BY is an email worm. The worm will infect Windows systems. The worm spreads through email and network. The worm also has a backdoor function, which opens a TCP port.
The infected email carries a spoofed 'From' address picked up randomly from the infected system.
The subject of the infected mail will be blank.
The body of the infected mail will be any one of the following:
Annes
Alice
Alyce
Avice
Andrew
Androw
Androwe
Anthonie
Anthony
Anthonye
Bennet
Bennett
Cybil
Christean
Christian
Constance
Daniel
Danyell
Dorithie
Dorothee
Dorothy
Edmond
Edmund
Edward
Edwarde
Edmonde
Elizabeth
Elizabethe
Ellen
Ellyn
Emanual
Emanuel
Emanuell
Ester
Frances
Francis
Fraunces
Gabriell
Geoffraie
George
Grace
Happy New Year
Harry
Harrye
Henrie
Henry
Henrye
Hughe
Humphrey
Humphrie
Isabel
Isabell
James
Jeames
Jeffrey
Jeffrye
Joane
Johen
Josias
Judeth
Judith
Judithe
Katherine
Katheryne
Leonard
Leonarde
Margaret
Margarett
Margerie
Margerye
Margret
Margrett
Marie
Martha
Marye
Michael
Mychaell
Nathaniel
Nathaniell
Nathanyell
New 2006
New Year's
New Year's Day.
Nicholas
Nicholaus
Nycholas
Password:
Peter
Ralph
Rebecka
Richard
Richarde
Robert
Roberte
Roger
Rycharde
Samuell
Sidney
Sindony
Stephen
Susan
Susanna
Suzanna
Sybell
Sybyll
Syndony
Text
The password is
Thomas
Valentyne
We congratulate happy New Year
William
Winifred
Wynefrede
Wynefreed
Wynnefreede
The infected attachment will be any one of the following;
Its backdoor capabilities can also set up the infected system as a Web server, to which a remote user can upload or download a possibly malicious file.
Proland
Software is the developer of Protector Plus range of antivirus software
packages. Protector Plus 2007 is available for Windows Vista, Windows 95/98/Me, Windows
XP, Windows NT/2000/2003 servers and workstations, MS-Exchange 2000/2003, MS-DOS
and NetWare servers.
Protector Plus range of antivirus products
offer on-line virus detection and removal. All the packages have the ability
to detect and isolate all types of viruses, trojans, worms and other types
of malware.
These products are updated on a continuous basis and the latest upgrades
for all the platforms are made available for downloading from this site.