03.75.2004 - Level 3 Virus: W32.Beagle.M@mm Removal Tool v1.0.0
|
The W32.Beagle.M@mm is a polymorphic mass-mailing worm that uses its own SMTP engine to spread through email. Like previous Beagle variants, this worm opens a backdoor (it listens on TCP port 2556), and attempts to spread through file-sharing networks by copying itself to folders that contain "shar" in their names. W32.Beagle.M@mm also infects files with the EXE extension.
The email has the following characteristics:
From: spoofed to appear as though its coming from the one of the following addresses at the recipient's domain: management, administration, staff, noreply, support
Subject:
Attachment: A randomly named .exe file, stored inside a .zip file or a .rar file, or a .pif file. The .zip and .rar files file may be password-protected.
- Download Removal Tool
- View Threat Information
- Visit Symantec Corporation
|
|
|