The Web    Google
9/3: Worm Ends Antivirus Processes

9/3: Worm Ends Antivirus Processes
September 3, 2004

Bagle.AY is a worm that ends processes belonging to several antivirus update programs, among other applications.

Bagle.AY spreads via e-mail, in a message with an attached file with a random name and a ZIP extension. This file contains an HTML file, together with a hidden EXE file. This executable file is run when the user opens the HTML file.

Once it has affected the computer, Bagle.AY attempts to download a fake JPG file from several websites. If successful, Bagle.AY will start spreading from the computer.

Technical details are at Panda Software page.

  • 9/7: Sdbot-RY Worm Runs in Background
  • Sue a Spoofer Today
  • 8/23: W64.Shruggle.1318 Infects PE Files
  • Would Do-Not-Spam List Benefit the Enterprise?
  • 6/14: Dansh.worm!irc an IRC Bot
  • Security Execs Identify Top Issues for 2005
  • 6/4: Agobot.300544 a Memory Resident
  • HP Cuts to the Middle of Disaster Recovery
  • 10/1: Spybot-EAS Remotely Controlled
  • Enterprise IM Spurs Privacy Concerns
  • 10/29: Singu-B Allows Remote Access
  • Security Camera News