1. Home
  2. Computing & Technology
  3. Antivirus Software

Bagle.U worm

By Mary Landesman, About.com

Name:
Bagle.U worm
Also known as:
W32/Bagle.U@MM, I-Worm.Bagle.U, W32.Beagle.U@mm, WORM_BAGLE.U
Type:
Mass-mailing email worm that opens TCP port 4751 on infected systems and sends HTTP notice to the worm's author.
Discovered:
March 26, 2004
Email characteristics:
Bagle.U arrives with no subject line and no message body from a spoofed sender. The blank email message carries a randomly named .exe attachment. Email addresses are harvested from infected users' systems and used in both the From and To fields. Bagle.U sends the email using its own SMTP engine.When the attachment is opened, if the Microsoft Hearts game is installed on the user's PC, Bagle.U will first launch MSHEARTS.EXE.
System impact:
Bagle.U drops a copy of itself to the Windows System directory as gigabit.exe and modifies the following registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

adding the vaule:

"gigabit.exe" = %sysdir%\gigabit.exe

where %sysdir% represents the path to the user's Windows System directory.

Bagle.U also adds the following registry key and values:

HKEY_CURRENT_USER\Software\Windows2004 "fr1n"

HKEY_CURRENT_USER\Software\Windows2004 "gsed"Bagle.U opens TCP port 4751 and sends notice (port number and ID) to the worm's author via HTTP.

Manual removal:
Use the Windows Task Manager to shutdown the gigabit process. Delete the registry modifications made. Delete gigabit.exe.
Explore Antivirus Software
About.com Special Features

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

Easy ways to connect two computers for networking purposes. More >

  1. Home
  2. Computing & Technology
  3. Antivirus Software

©2009 About.com, a part of The New York Times Company.

All rights reserved.