VIRUS ALERT
October 28, 2004
HIGHPanda Virus Alert - Bagle.BC Red Alert Status
Panda Software Upgrades Security Threat to Red Alert Status as Bagle.BC
Continues Causing Incidents Worldwide, New Variants, BD and BE, Have
Appeared
- Bagle.BC is spreading rapidly worldwide, causing more and more
incidents, and now appears in the top half of the ranking of the
viruses most frequently detected by Panda ActiveScan
- Panda Software has made its free PQRemove utility available to all
users to effectively detect and eliminate Bagle.BC from affected
computers
- Over the next few hours, thousands of emails infected by one of these
worms will be circulating, and therefore the probability of a computer
being infected is getting higher. New variants are also likely to
emerge
- TruPrevent Technologies, “the most intelligent technologies to combat
unknown viruses and intruders,” Have effectively detected and blocked
these 3 new variants of the Bagle worm, without needing to be able to
identify them first
Glendale, CA - October 29, 2004 - The Bagle.BC worm is increasing its
already high rate of propagation, causing more and more incidents in users’
computers worldwide. Just a few hours after it appeared, it has made the
top half of the ranking of the viruses most frequently detected by the
online antivirus scanner, Panda ActiveScan. Even so, the number of
incidents caused by this worm is expected to continue increasing and new
variants are expected to emerge over the next few hours.
This has prompted Panda Software to declare a Red Virus Alert as a
preventive measure, so that all users can protect themselves against these
worms and prevent their computers from being infected. Similarly, companies
also risk their communications being slowed down by the large number of
emails that mail servers will have to process.
In addition to this worm, PandaLabs has detected the appearance of the two
new variants, BD and BE, of the same worm. As with Bagle.BC, Panda Software
clients that have already installed the new TruPrevent Technologies have
preventive protection against these worms, as they were able to detect and
block these new variants of the Bagle worm without needing to be able to
identify them first (more information about the new TruPrevent Technologies
at http://www.pandasoftware.com/truprevent).
Panda Software has made the corresponding updates available to its clients
to detect and disinfect these new worms. What’s more, it has made its free
PQRemove utility available to all users to effectively detect and eliminate
Bagle.BC from computers affected by this worm. Users can download this
utility from the following address
http://www.pandasoftware.com/download/utilities/
With the appearance of these new variants, the objective of the authors of
these worms is obvious: release the maximum number of malicious code to
increase the huge probability of computers being hit by one of them.
According to Luis Corrons: “this is a technique that is being used more
often. Virus creators know that the reaction time to new threats is
critical, and therefore, the faster they can release various viruses, the
easier it is for users to take too long to update their system. This
problem is resolved with our TruPrevent Technologies, which have blocked
these new worms without users needing to do a thing.”
The new variants detected are very similar to Bagle.BC, a worm that spreads
via email, networks and P2P applications like KaZaA. However, they do have
some difference, such as the number of files they generate on the computers
they infect.
The three new Bagle worms share the fact that they have been designed to
end the processes belonging to antivirus and security applications running
in memory. However, none of these worms can affect the functioning of the
TruPrevent Technologies.
To prevent incidents involving the new variants of Bagle, Panda Software
advises users to take precautions and to keep their antivirus software
updated.
Panda Software’s clients can already access the updates for installing the
new TruPrevent Technologies along with their antivirus protection,
providing a preventive layer of protection against these and other new
malicious code. For users with a different antivirus program installed,
Panda TruPrevent Personal is the perfect solution, as it is both compatible
with and complements these products, providing a second layer of preventive
protection that acts while the new virus is still being studied and the
corresponding update is incorporated into traditional antivirus programs,
decreasing the risk of infection. More information about TruPrevent
Technologies at
http://www.pandasoftware.com/truprevent
For further information about Bagle.BC, Bagle.BD and Bagle.BE, visit Panda
Software's Virus Encyclopedia at:
http://www.pandasoftware.com/virus_info/encyclopedia/
In addition, users can scan their computers online for free with Panda
ActiveScan, available at
http://www.pandasoftware.com
About PandaLabs
On receiving a possibly infected file, Panda Software's technical staff get
right to work. The file is analyzed and depending on the type, the action
taken may include: disassembly, macro scanning, code analysis etc. If the
file does in fact contain a new virus, the disinfection and detection
routines are prepared and quickly distributed to users.
For more information: http://www.pandasoftware.com/virus_info
For more information:
Alan Wallace
[email protected]
Original source: panda-us-virusalert-2004-10-29-baglebc-redalert.doc

