SECURITY INFO
Latest Threats
Spyware
Spam
Phishing
Hoaxes
PandaLabs
Virus map
Panda Virusometer
TRAINING
General concepts
Technical details
Virus FAQs
Practical tips
DOWNLOADS
Repair utilities
Does my antivirus work?
ActiveScan Pro
Free Antivirus
HOME
What is VirusPortal?
Newsletters
HOME SECURITY INFO TRAINING DOWNLOADS WEBMASTERS
Security Info / Virus encyclopedia / At a glance
Find:    in:  
 

 Bagle.AH
Threat Level:  High
Distribution:  Medium
Damage: Severe
The Threat Level varies according to the Distribution and Damage levels
 
 Common name: Bagle.AH
 Technical name: W32/Bagle.AH.worm
 Threat Level: Low
 Type: Worm
 Effects:  

It opens a port and waits for remote connections, ends processes belonging to antivirus programs and firewalls, and connects to web pages that contain PHP scripts.

 Systems affected: Windows XP/2000/NT
 First detected on: July 19, 2004
 Detection updated on: April 6, 2006
 In circulation? No
  
Panda QuickRemover
  Brief Description
 

Bagle.AH is a worm that affects Windows XP/2000/NT computers only. Bagle.AH opens and listens to a TCP port, waiting for remote connections. By doing so, it allows hackers to gain remote control over the affected computer in order to carry out malicious actions that would compromise user's confidentiality or impede normal work.

Bagle.AH ends processes belonging to antivirus programs and firewalls, among others. This leaves the affected computer vulnerable to the attack of other malware.

Additionally, this worm connects to several web pages that contain a PHP script.

It also eliminates the entries in the Windows Registry belonging to several variants of the worm Netsky.

Bagle.AH spreads via e-mail in a message with variable characteristics and through peer-to-peer file sharing programs (P2P).

[ top ]  

  Visible Symptoms
 

Bagle.AH is difficult to recognize, as it does not display any messages or warnings that indicate it has reached the computer.



[ top ]  

Last updated:  April 6, 2006 

 

  © Panda 2009 | Free Antivirus | Make this your home page | Bookmark this page | Send page | Contact us | Legal notice | Privacy Policy