SECURITY INFO
Latest Threats
Spyware
Spam
Phishing
Hoaxes
PandaLabs
Virus map
Panda Virusometer
TRAINING
General concepts
Technical details
Virus FAQs
Practical tips
DOWNLOADS
Repair utilities
Does my antivirus work?
ActiveScan Pro
Free Antivirus
HOME
What is VirusPortal?
Newsletters
HOME SECURITY INFO TRAINING DOWNLOADS WEBMASTERS
Security Info / Virus encyclopedia / At a glance
Find:    in:  
 

 Bagle.A
Threat Level:  Low
Distribution:  Low
Damage: High
The Threat Level varies according to the Distribution and Damage levels
 
 Common name: Bagle.A
 Technical name: W32/Bagle.A.worm
 Threat Level: Low
 Alias: W32/Bagle@MM, I-Worm.Bagle, W32.Beagle.A@mm, W32/Bagle-A, Bagle
 Type: Worm
 Effects:  

It does not have any destructive effects. It spreads via e-mail.

 Systems affected:  Windows 2003/XP/2000/NT/ME/98/95
 First detected on: Jan. 19, 2004
 Detection updated on: April 10, 2006
 In circulation? No
  
Panda QuickRemover
  Brief Description
 

Bagle.A is a worm without destructive effects that spreads via e-mail in a message with the subject Hi and an attached file with a name that consists of several random characters and has an EXE extension.

Bagle.A runs only if the system date is January 28, 2004 or previous.

Bagle.A attempts to connect to several web pages through the port 6777, in order to update itself and make an inventory of the affected users. However, these web pages have been disabled. In addition, it has code that allows it to download files from the Internet and run them on the affected computer.

[ top ]  

  Visible Symptoms
 

Bagle.A is easy to recognize, as it reaches the computer via e-mail in a message with the subject Hi and an attached file with a name that consists of several random characters and has an EXE extension.

The attached file has the same icon as the Windows Calculator:

The first time the attached file is run, the worm runs the Windows Calculator (CALC.EXE file).



[ top ]  

Last updated:  April 10, 2006 

 

  © Panda 2009 | Free Antivirus | Make this your home page | Bookmark this page | Send page | Contact us | Legal notice | Privacy Policy