Virus alert!

SagaLore

Elite Member
Dec 18, 2001
24,036
21
81
I can't identify an infector file I just quarantined at our gateway. InoculateIT and Command AV can't detect it.

It came as Alive_Condom.vbs - and contained simple code with a long ASCII array it uses to assemple an executable file, then runs that file. I deleted the lines for the execution and ran it, to generate vss_2.exe. Scanning that also yields no results. I don't find any mention of a new virus like this.

Anybody else receive something like this?

edit:
Okay I found it. I used Panda's online scan to detect it.

It's Bagel.AB. When will these variants ever stop???
 

techfuzz

Diamond Member
Feb 11, 2001
3,107
0
76
I think we got something like that the other day. Our gateway stopped a message identified as a "bloodhound virus" but it had no official name. We hadn't ever received anything like that before.

techfuzz
 

SagaLore

Elite Member
Dec 18, 2001
24,036
21
81
Okay I found it. I used Panda's online scan to detect it.

It's Bagel.AB.
 

FoBoT

No Lifer
Apr 30, 2001
63,084
15
81
fobot.com
Originally posted by: techfuzz
Our gateway stopped a message identified as a "bloodhound virus" but it had no official name. We hadn't ever received anything like that before.

techfuzz

somebody came in with thier laptop infected with this today

i grabbed her PAB and spoofed email to a bunch of people trying to spread itself
 

Harvey

Administrator<br>Elite Member
Oct 9, 1999
35,059
73
91
I searched Computer Associates' Virus Info Center for Alive_Condom and found this info. They identify it as Win32.Bagle.X.
The attachment name is chosen from the following list:

Alive_condom
Counter_strike
Details
Details
Document
Half_Live
I_search_for_you
Info
Information
Joke
Loves_money
Manufacture
Message
MoreInfo
Nervous_illnesses
Readme
Smoke
Toy
You_are_dismissed
You_will_answer_to_me
Your_complaint
Your_money
text_document
the_message
the_message

The extension can be one of the following:

.exe
.scr
.com
.zip
.vbs
.hta
.cpl
Searching Symantec for Bagle.X gets this info, dated 4/2April 26, 2004 which they call Beagle.W. They also show an even newer alert, today, for another varient to which they assign the .X extension, W32.Beagle.X@mm. :frown:

Looks like Bagle and Beagle are interchangable, but the dog wouldn't go as well with lox cream cheese. :p
 

gistech1978

Diamond Member
Aug 30, 2002
5,047
0
0
i think i got this one this AM
its long since deleted, but it was a picture of a girl, and the files attached were a jpg and information.cpl
 

911paramedic

Diamond Member
Jan 7, 2002
9,448
1
76
An email was sent to you that we have identified as containing a virus. Below find the details of the infected message:

From: cscappos@earthlink.net
Date: Tue, 27 Apr 2004 23:11:31 -0400
Virus Name: W32/Netsky.p@MM
Infected Attachments: 0000014a.EML, /0000014a.EML, /0000014a.EML/0000008d.EML, /message.scr

Sincerely,

The Cox High Speed Internet Team

Got this message today, I guess they delete these before I even get them now.
 

KLin

Lifer
Feb 29, 2000
30,459
765
126
I got an email in my yahoo account with a .vbs attachment. I wanted to d/l it and take a look at the code, but it wouldn't let me. It showed the virus as being W32.Beagle.X@mm
 

Zim Hosein

Super Moderator | Elite Member
Super Moderator
Nov 27, 1999
65,414
407
126
Originally posted by: silverpig
NAV has updated its virus definitions twice on me today.

Same here!

Thanks for the post SagaLore :beer:
 

SagaLore

Elite Member
Dec 18, 2001
24,036
21
81
What gets me, is the fact that it is a simple vbs script and none of the virus scanners were picking it up. It obvious it's a virus when you look at the script. It creates an exe file, then executes it - at least heuristics should be all over it! But nope...

This shows how important a personal firewall can be - one that protects applications and authorizes application activity (zone alarm, sygate, etc.). If I were a gullible user and double clicked on that vbs script, in theory the personal firewall would either ask me if that exe was okay to run, or look at the activity over port 25 and stop it.
 

MikePanic

Senior member
Apr 5, 2004
913
0
0
at least 10-15% of my email's lately have been infected w/ something or other... this is really starting to get old
 

earthling30

Senior member
Mar 18, 2004
483
0
0
I agree! It seems to be coming from the spammers mostly on my end of the States! Ha, I'm so glad for them! :laugh: What goes around comes around. Not that I had anything to do with those viruses floating around, I'm just a potential victim like every other user on the internet.
 

techfuzz

Diamond Member
Feb 11, 2001
3,107
0
76
I like that we block every vbs file that comes through the gateway where I work. There isn't a single change that a user can get it through via email and causing a catastrophe here.

techfuzz
 

SagaLore

Elite Member
Dec 18, 2001
24,036
21
81
Originally posted by: techfuzz
I like that we block every vbs file that comes through the gateway where I work. There isn't a single chance that a user can get it through via email and causing a catastrophe here.

techfuzz

Same here. I block every executable (exe, com, vbs, scr, etc.) and archive it into a mailbox, then send a notice to the user. If the user was expecting it for legitimate reasons, they'll forward the notice to me and I'll release it for them if I determine it's safe.

Our network stays 100% virus free.

I'm actually having more problems with spyware than anything...
 

MazerRackham

Diamond Member
Apr 4, 2002
6,572
0
0
Info from UC Irvine:

Last night around 8:30pm, a new variant of the phatbot worm hit
campus. This one exploits one of the vulnerabilties that was patched
by one of the Microsoft patches (MS04-011) that were released 2 weeks
ago. As of 7am this morning almost 200 campus systems have been
infected with this worm. A list of systems is below - if any are in
your area please get them cleaned up ASAP.
 

SuepaFly

Senior member
Jun 3, 2001
972
0
0
I've been getting virus infected email for a few days now. Pretty tricky too since they have something on the bottom like a "scanned by AVG no virus detected". Also my friend sent me some email from a hotmail address saying "I found you on a spamming list, is this true?" Didn't think hotmail could do that.
 

Jzero

Lifer
Oct 10, 1999
18,834
1
0
Originally posted by: SagaLore
Originally posted by: techfuzz
I like that we block every vbs file that comes through the gateway where I work. There isn't a single chance that a user can get it through via email and causing a catastrophe here.

techfuzz

Same here. I block every executable (exe, com, vbs, scr, etc.) and archive it into a mailbox, then send a notice to the user. If the user was expecting it for legitimate reasons, they'll forward the notice to me and I'll release it for them if I determine it's safe.

Our network stays 100% virus free.

I'm actually having more problems with spyware than anything...

Me too. Between SUS and rule-based file filtering, I don't lose much sleep over viruses these days.