Skip Over Navigation Links
Center for Information TechnologyAntivirus
Antivirus Home Page
Contact Us
Questions or Comments
Disclaimers

Software
Current client downloads:
 VScan Engine/Dat (SuperDat) -5.2.00/4.0.5378
 VirusScan Enterprise 8.5i (with Patch 6) - Windows NT/2000/XP/2003
 VirusScan Enterprise 7.1 - Windows NT/2000/XP/2003
 Virex (OS X) Engine/Def - 7.2(v1.1)/080903
 Virex (OS 9.x) Engine/Def - 6.2/071001
 Linux & Solaris Engine/Dat - 5.2.00/4.0.5196
 Symantec Antivirus - 10.1.7.7000
 Symantec Antivirus - 10.2
 Clean Boot 1.0
 Stinger v3.8.0 virus removal tool (Updated 09/10/07)
Current server downloads:
 VirusScan Enterprise 8.5
 VirusScan Enterprise 7.1
 NetShield NetWare - 4.6.2
 NetShield NetWare - 4.6.3
 NetShield NetWare Engine Update - 4.4.00
 ePO agent for NetWare
 ScanMail eManager - 3.0

Information
 ePO 3.0/VirusScan 7.0 Presentation
 Virex 7.x Installation Instructions
 VirusScan FAQs
 VirusScan Instructions
 Additional Resources

Archives
 List of Viruses

Virus Alerts

W32/Bagle.ah@mm Last Updated 7/19/04 7:00PM

CIT has been notified of a new email virus called W32/Bagle.ah@mm. This is a mass-mailing worm that harvests email addresses from infected machines. Emails are forged to appear to be sent by an address collected from the infected machine.

From: Spoofed email address

Examples of subjects lines are:

  • Password: %s
  • Pass - %s
  • Key - %s
  • Re:
  • foto3
  • fotogalary
  • fotoinfo
  • Lovely animals
  • Animals
  • Predators
  • The snake
  • Screen

Body: is empty

Attachment:(Two attachments, Possibly a .bmp and one of the following file types: EXE, .SCR, .COM, .ZIP, .CPL)

Example

  • foto3.exe
  • foto2.scr
  • foto1.com
  • Secret.zip
  • Doll.cpl
  • Garry.exe
  • Cat.scr
  • Dog.com
  • Fish.zip

The .bmp contains a password to open the attachment if it is a password protected .zip

The worm also propagates through peer to peer networks with open directories that contain the string shar

McAfee (formerly NAI) has released SuperDat 4379 and later to detect and remove W32/Bagle.ah@mm.

Symantec will be releasing definitions dated 4/26/04 and later to detect and remove beagle.w@MM.

For more Information:

http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=126795 from McAfee.

http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ag@mm.html from Symantec.

This archive is not intended to be comprehensive. For a more complete virus library, please visit NAI's Virus Information Library at http://vil.nai.com.

Contact NIH Help Desk for assistance:
866-319-4357 (toll free), 301-496-4357 (6-HELP) (local), 301-496-8294 (TDD)
http://ithelpdesk.nih.gov/support
Register for iForgotMyPassWord

National Institutes of HealthCenter for Information Technology
National Institutes of Health
Bethesda, Maryland 20892

Questions or Comments | Disclaimers | Privacy Policy

Department of Health and Human ServicesHealth and Human Services
Washington, D.C. 20201
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -