wipe-deletion-erasure-purge


I-Worm.Bagz.g

I-Worm.Bagz.g

CyberScrub AntiVirus
Research Bank

This worm spreads via the Internet as an attachment to infected messages. It sends messages to all email addresses harvested from the victim computer.

The worm itself is a Windows PE EXE file approximately 167KB in size, packed using UPX. The unpacked file is approximately 200KB in size.

Installation

Once launched, the worm creates the following files in the Windows system directory:

C:\WINDOWS\SYSTEM32\sysinfo32.exe
C:\WINDOWS\SYSTEM32\trace32.exe

It also copies itself to the Windows system directory as:

C:\WINDOWS\SYSTEM32\sqlssl.doc           .exe

Bagz then creates the following entry in the system registry:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Xuy v palto]
Propagation via email:

The worm searches for files with the extensions listed below:

TBB
tbb
TBI
tbi
DBX
dbx
HTM
htm
TXT
txt

and sends itself to all email addresses harvested from these files.

The worm establishes a direct connection to the recipient's SMTP server in order to send messages.

Messages are not sent to addresses which contain the following text strings:

@avp
@foo
@iana
@messagelab
@microsoft
abuse
admin
administrator@
all@
anyone@
bsd
bugs@
cafee
certific
certs@
contact@
contract@
feste
free-av
f-secur
gold-
gold-certs@
google
help@
hostmaster@
icrosoft
info@
kasp
linux
listserv
local
netadmin@
news
nobody@
noone@
noreply
ntivi
oocies
panda
pgp
postmaster@
rating@
root@
samples
sopho
spam
support
support@
unix
update
webmaster@
winrar
winzip
Infected messages: Message subject (chosen at random from the list below):
ASAP
Administrator
Allert!
Amirecans
Att
attach
attachments
best regards
contract
Have a nice day
Hello
Money
office
please responce
re: Andrey
re: order
re: please
Read this
Russian's
text
toxic
urgent
Vasia
waiting
Warning
Message body (chosen at random from the list below):
  • Did you get the previous document I attached for you?
    I resent it in this email just in case, because I
    really need you to check it out asap.
    Best Regards

  • Hi
    I made a mistake and forgot to click attach
    on the previous email I sent you. Please give me
    your opinion on this opportunity when you get a chance.
    Best Regards

  • Hi
    I was supposed to send you this document yesterday.
    Sorry for the delay, please forward this to your family if possible.
    It contains important info for both of you.

  • Hi
    Sorry, I forgot to send an important
    document to you in that last email. I had an important phone call.
    Please checkout attached doc file when you have a moment.
    Best Regards

  • Hi
    I was in a rush and I forgot to attach an important
    document. Please see attached doc file.
    Best Regards,

  • Sorry to bother you, but I am having a problem receiving your emails.
    I am responding to your last email in the attached file.
    Please get back to me if there is any problem reading the attachment.

  • I am responding to your last email in the attached file.
    I had a delivery problem with your inbox, so maybe you'll receive this now.

  • Can you please check out the email I have attached?
    For some reason, I received only part of your last several emails.
    I want to make sure that there are no problems with either of our accounts.

  • This email is being sent as attachment because
    it was previously blocked by your email filters.
    Please view the attachment and respond.
    Thanks

  • I resent this email as attachment because
    it was previously blocked by your email filters.
    Please read the attachment and respond.
    Thanks

  • I apologize, but I need you to verify
    that I have the correct contact info for you.
    My system crashed last weekend and
    I lost most of my friends and work contacts.
    Please check the attached (.pdf) and
    please let me know if your info is current.

  • My last email to you was returned.
    The reason is that I am not currently
    added to your allowed contact list.
    Please add my updated contact info
    provided in the attached (.pdf) file
    so I can send you emails in the future.
    Sincerely

  • I have updated my email address
    See the (.pdf) file attached and
    please respond if you have any questions.

  • We have made recent updates to our database.
    Please verify your mailing address on file is correct.
    We have attached a (.pdf) sheet for you to use for your response.

  • Hello
    Our contact information has changed.
    See the attached (.pdf) sheet for details.
    Sincerely,

  • ***URGENT: SERVICE SHUTDOWN NOTICE***
    Due to your failure to comply with our email
    Rules and Regulations, your email account has been
    temporarily suspended for 24 hours unless we are contacted regarding
    this situation.
    You must read the attached document for further
    instructions. Failure to comply will result in termination of your account.
    Regards,
    Net Operator
    ***URGENT: SERVICE SHUTDOWN NOTICE***

  • ***ATTENTION: YOUR EMAIL IS NOT BEING DELIVERED!***
    You are currently unable to send emails.
    This may be a billing issue.
    Please call the billing center.
    The # for the billing office is located in the attached
    contact list for your convenience.
    ***ATTENTION: YOUR EMAIL IS NOT BEING DELIVERED!***

  • ***YOUR MESSAGE HAS BEEN RECOGNIZED AS SPAM***
    Hello,
    The previous email you sent has been recognized as spam.
    This means your email was not delivered to your friend or client.
    You must open the attached file to receive more information.
    ***YOUR MESSAGE HAS BEEN RECOGNIZED AS SPAM***

  • Hello,
    What version of windows you are using?
    This last document I received from you came out weird.
    Please see the attached word file and resend the file to me.
    Many thanks,
    User

  • Hello,
    My PC crashed while I was sending that last email.
    I have re-attached the document of yours that I discovered.
    Please read attached document and respond ASAP.
    Sincerely,
    User

  • Hello,
    Your email was sent in an INVALID format.
    To verify this email was sent from you,
    simply open the attached email (.eml) file
    and click yes in the sender options box.
    Thank You,
    User

  • Hello,
    Your email was received.
    YOUR REPLY IS URGENT!
    Please view the attached text file for instructions.
    Regards,
    User

  • Hello,
    I was in a hurry and I forgot to attach an important
    document. Please see attached.
    Best Regards,
    User

  • Hello,
    I resent this email as attachment because
    it was previously blocked by your email filters.
    Please read the attachment and respond.
    Thanks,User

  • Hello,
    Sorry, I forgot to attach the new contact information.
    Please view the attached (.pdf) contact sheet.
    Sincerely, User

Attachment name (chosen at random from the list below):
about.zip
admin.zip
archivator.zip
archives.zip
ataches.zip
backup.zip
docs.zip
documentation.zip
help.zip
inbox.zip
manual.zip
outbox.zip
payment.zip
photos.zip
rar.zip
readme.zip
save.zip
zip.zip

about.doc                    .exe
admin.doc                    .exe
archivator.doc                    .exe
archives.doc                   .exe
ataches.doc                   .exe
backup.doc                    .exe
docs.doc                   .exe
documentation.doc                   .exe
help.doc                   .exe
inbox.doc                   .exe
manual.doc                   .exe
outbox.doc                   .exe
payment.doc                   .exe
photos.doc                   .exe
rar.doc                   .exe
readme.doc                   .exe
save.doc                   .exe
sqlssl.doc                   .exe
zip.doc                   .exe
Payload

Bagz alters the %System%\DRIVERS\ETC\HOSTS file by writing the following text to it:

127.0.0.1 ad.doubleclick.net 
127.0.0.1 ad.fastclick.net 
127.0.0.1 ads.fastclick.net 
127.0.0.1 ar.atwola.com 
127.0.0.1 atdmt.com 
127.0.0.1 avp.ch 
127.0.0.1 avp.com 
127.0.0.1 avp.ru 
127.0.0.1 awaps.net 
127.0.0.1 banner.fastclick.net 
127.0.0.1 banners.fastclick.net 
127.0.0.1 ca.com 
127.0.0.1 click.atdmt.com 
127.0.0.1 clicks.atdmt.com 
127.0.0.1 dispatch.mcafee.com 
127.0.0.1 download.mcafee.com 
127.0.0.1 download.microsoft.com 
127.0.0.1 downloads.microsoft.com 
127.0.0.1 engine.awaps.net 
127.0.0.1 fastclick.net 
127.0.0.1 f-secure.com 
127.0.0.1 ftp.f-secure.com 
127.0.0.1 ftp.sophos.com 
127.0.0.1 go.microsoft.com 
127.0.0.1 liveupdate.symantec.com 
127.0.0.1 mast.mcafee.com 
127.0.0.1 mcafee.com 
127.0.0.1 media.fastclick.net 
127.0.0.1 msdn.microsoft.com 
127.0.0.1 my-etrust.com 
127.0.0.1 nai.com 
127.0.0.1 networkassociates.com 
127.0.0.1 office.microsoft.com 
127.0.0.1 phx.corporate-ir.net 
127.0.0.1 secure.nai.com 
127.0.0.1 securityresponse.symantec.com 
127.0.0.1 service1.symantec.com 
127.0.0.1 sophos.com 
127.0.0.1 spd.atdmt.com 
127.0.0.1 support.microsoft.com 
127.0.0.1 symantec.com 
127.0.0.1 update.symantec.com 
127.0.0.1 updates.symantec.com 
127.0.0.1 us.mcafee.com 
127.0.0.1 vil.nai.com 
127.0.0.1 viruslist.ru 
127.0.0.1 windowsupdate.microsoft.com 
127.0.0.1 www.avp.ch 
127.0.0.1 www.avp.com 
127.0.0.1 www.avp.ru 
127.0.0.1 www.awaps.net 
127.0.0.1 www.ca.com 
127.0.0.1 www.fastclick.net 
127.0.0.1 www.f-secure.com 
127.0.0.1 www.kaspersky.ru 
127.0.0.1 www.mcafee.com 
127.0.0.1 www.my-etrust.com 
127.0.0.1 www.nai.com 
127.0.0.1 www.networkassociates.com 
127.0.0.1 www.sophos.com 
127.0.0.1 www.symantec.com 
127.0.0.1 www.trendmicro.com 
127.0.0.1 www.viruslist.ru 
127.0.0.1 www3.ca.com
127.0.0.1 localhost

This means that the user will be unable to access these resources.

The worm deletes system registry entries which contain the following text strings:

804mbd1.chk
804mbd1.img
aboutplg.dll
alert.zap
appinit.ini
apwcmdnt.dll
apwutil.dll
ashavast.exe
ashbug.exe
ashchest.exe
ashdisp.exe
ashldres.dll
ashlogv.exe
ashmaisv.exe
ashpopwz.exe
ashquick.exe
ashserv.exe
ashsimpl.exe
ashskpcc.exe
ashskpck.exe
aswboot.exe
aswregsvr.exe
aswupdsv.exe
avcompbr.dll
avres.dll
bootwarn.exe
camupd.dll
ccavmail.dll
ccimscan.dll
ccimscn.exe
cerbprovider.pvx
cfgwiz.exe
cfgwzres.dll
defalert.dll
djsalert.dll
dunzip32.dll
edisk.dll
email.zap
emscnres.dll
filter.zap
firewall.zap
framewrk.dll
ftscnres.dll
idlock.zap
imscnbin.inf
imscnres.inf
ltchkres.dll
mcappins.exe
mcavtsub.dll
mcinfo.exe
mcmnhdlr.exe
mcscan32.dll
mcshield.dll
mcshield.exe
mcurial.dll
mcvsctl.dll
mcvsescn.exe
mcvsftsn.exe
mcvsmap.exe
mcvsrte.exe
mcvsscrp.dll
mcvsshl.dll
mcvsshld.exe
mcvsskt.dll
mcvsworm.dll
mghtml.exe
mpfagent.exe
mpfconsole.exe
mpfservice.exe
mpftray.exe
mpfupdchk.dll
mpfwizard.exe
mvtx.exe
n32call.dll
n32exclu.dll
naiann.dll
naievent.dll
navap32.dll
navapscr.dll
navapsvc.exe
navapw32.dll
navapw32.exe
navcfgwz.dll
navcomui.dll
naverror.dll
navevent.dll
navlcom.dll
navlnch.dll
navlogv.dll
navlucbk.dll
navntutl.dll
navoptrf.dll
navopts.dll
navprod.dll
navshext.dll
navstats.dll
navstub.exe
navtasks.dll
navtskwz.dll
navui.dll
navui.nsi
navuihtm.dll
navw32.exe
navwnt.exe
netbrext.dll
ntclient.dll
oeheur.dll
officeav.dll
opscan.exe
outscan.dll
outscres.dll
patch25d.dll
patchw32.dll
persfw.exe
pfui.dll
pfwadmin.exe
probegse.dll
programs.zap
ptchinst.dll
qconres.dll
qconsole.exe
qspak32.dll
quar32.dll
quarantine
quaropts.dat
s32integ.dll
s32navo.dll
savrt.sys
savrt32.dll
savrtpel.sys
savscan.exe
scan.dat
scandlvr.dll
scandres.dll
scanmgr.dll
scanserv.dll
sched.exe
scriptui.dll
scrpres.dll
scrpsbin.inf
scrstres.inf
sdpck32i.dll
sdsnd32i.dll
sdsok32i.dll
sdstp32i.dll
security.zap
shextbin.inf
shextres.inf
shlres.dll
ssleay32.dll
statushp.dll
symnavo.dll
tutorwiz.dll
vsagntui.dll
vsavpro.dll
vsdb.dll
vsmon.exe
vsoui.dll
vsoupd.dll
vsowow.dll
vsruledb.dll
vsvault.dll
wormres.dll
zatutor.exe
zauninst.exe
zav.zap
zl_priv.htm
zlclient.exe
zlparser.dll
zonealarm.exe

By deleting these values, the worm attempts to block the work of a number of antivirus solutions and firewalls.

Check out if we have free removal tool for this virus


CyberScrub AntiVirus provides state of the art security protection for five years- at one low price. Our award winning technology ensures protection against viruses, worms and trojans backed by top customer support and value.

 
Five Year Cost Comparison
Product Initial Cost Yearly Subscription X Four Years Total
Norton 2004 AntiVirus $49.95* $29.95 $119.80 $169.75
McAfee VirusScan $49.95* $19.95 $79.80 $129.75
CyberScrub AntiVirus $49.95 Included No Additional Cost $49.95
*All prices MSRP as published on respective sites.




It is only a matter of time before a virus, worm or Trojan horse wrecks havoc on your important data. Important files, records, family pictures- all at risk. Some dangerous programs can even ruin your hard drive beyond repair.

CyberScrub AntiVirus offers the most effective protection from all known and unknown viruses.

CyberScrub AntiVirus is powered by a unique integrated technology for virus detection, based on principles of multi-generation heuristic analysis. This allows the program to protect you from suspect “viral behavior”. This highly effective methodology repelled all attacks of each “I LOVEYOU’ viral variation without any additional antivirus database updates. No other technology, including Norton, Trend, or McAfee was able to accomplish this.

CyberScrub AntiVirus is powerful, yet its exceptional ease of use and installation make it acceptable for beginner to pro



CyberScrub Antivirus constantly scans your hard drive and files to identify, clean and destroy infected objects. With updates available every three hours, 24 hours a day, 365 days a year, you can count on CyberScrub to protect your valued data.

CyberScrub AntiVirus
Lifetime Edition

"For the Life of Your Computer"

Save $10 Now!
Limited Time

 


I-Worm.Bagz.g


Symantec Warns Of Flaw In Antivirus Program. More>>

CNN Legend Lynne Russell reports on CyberScrub AntiVirus for Tech Headline News.


















 
 

delete,deletion, file deletion, Internet clean up,privacy, HIPAA, Internet privacy, cookies, erase, erasure, shredder, wipe, overwrite, purge, deletion, security, file wipe, data destruction