|
Now Spammers steal your email ID
Not content with Spamming you, Spammers have ‘launched I.Worm.Bagle, which steals your email ID and uses your computer to mail more infected Spam. The worm is also called Beagle. The main intention of the worm authors is to harvest millions of e-mail IDs that they would presumably either sell or worse, use it themselves.
According to Govind Ramamurthy, CEO and MD of MicroWorld Technologies Inc, the worm is patterned after the recent "Sobig" and "Mimail" outbreaks, which also turned scores of computers into zombie machines that spammers can control remotely to send torrents of get-rich-quick and sex aid messages to other computer users.
He said that the worm has a built-in SMTP Proxy Server that allows the worm to remotely send hundreds of mails to other users. The e-mail infection or worm, contains a familiar subject line of "Hi" and an executable file attachment identified by ".exe". The body of the e-mail contains random characters. The virus is triggered once a computer user clicks on the attachment, setting in motion an aggressive e-mail harvesting program that scans all documents on the infected computer's network.
MicroWorld has provided the required vaccine to fight the viruses, which you can download by visiting http://www.mwti.net.
(PRWEB) January 25, 2004 --What is I-Worm.Bagle?
I.Worm.Bagle is a mass-mailing worm that accesses remote Web sites and sends email to any addresses it finds using its own SMTP engine. It is capable of harvesting millions of e-mail addresses from infected PCs. The worm appears to be the handiwork of spammers keen to collect a batch of e-mail addresses they can harvest and then re-sell to other spam e-mail marketers or keep for their own use.
The worm is supposed to be active till January 28, 2004.
How it spreads?
The worm arrives as an email with an infected executable attachment and is launched when the attachment is opened.
What do I do if my system is infected with the worm?
If your system is already infected take one of the following steps to remove the worm and safeguard your computer.
1) The latest virus vaccine update of eScan removes the worm from your system. Ensure that Internet access for your system is running. If you a eScan user right click on the eScan tray icon and click Download eScan update. The latest updates are downloaded, your system is scanned and the worm is removed.
OR
2) In Anti-Virus update, click a link to directly download the update.
3)Unfortunately, if you not a user of eScan we can still help you, download the free MicroWorld Anti Virus Toolkit (MWAV Tool Kit). The tool checks your machine for viruses and removes them. This tool cleans the registry and other system areas that can be damaged by viruses. It also checks system process running in the background. If any illegal dialers or sniffer tools have been installed they are detected and removed.
Technical Detail:
What does the worm do on execution?
1. Checks if the system date is later than January 28, 2004. If so, the worm will not do anything.
2. Adds itself to the Operating Systems files so that it is loaded every time the computer is switched on.
3. Scans the system for files with the extensions .wab, .txt, .htm, and .html, looks for email addresses within these files, and then emails itself to the addresses using its own SMTP engine.
About MicroWorld Technologies Inc.
MicroWorld Technologies Inc. is the publisher of world's first real time anti-virus and content security software eScan and MailScan, for desktops and mail servers.
|