Hides itself well, security firm says
AN INCARNATION of the Bagle worm which can spawn mass mailing attacks is on the loose today, a security firm has confirmed.
The worm typically comes with a subject line "Hi" and a message "Test", with a spoofed From address and a file size of 16,872 bytes, said Ken Dunham, security officer at iDEFENSE.
If the attached .EXE file is started, it makes a copy of itself in the Windows System directory of bbeagle.exe, and uses the calc.exe icon. It then attempts to download or connect to remote websites, while it also attempts to open TCP port 6667.
Dunham said the Bagle.A worm "does a great job of hiding the infection". It tampers with WIndows registry keys and, he said, may try and download the Mitglieder Trojan.
Source.
More
here.