Virus type: Worm

Destructive: No

Aliases: W32/Bagle.n@MM

Description:

As of March 13, 2004 10:45 AM (PST), TrendLabs HQ received several reports of this new BAGLE variant.

This file infector searches for files with certain extension names, from which it gathers target recipients. Using its own SMTP (Simple Mail Transfer Protocol) engine, it sends out email messages with a spoofed return address to the gathered email addresses and adds itself as an attachment.

This virus also spreads by dropping files in folders that have the text string "shar", for example, C:\Program Files\Kazaa\My Shared Folder.

It also has the ability to terminate certain process, which are usually related to antivirus and firewall applications.

It runs on Windows 95, 98, ME, 2000 and XP.

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE_BAGLE.N