Panda Security
VIRUS ALERT
October 28, 2004
HIGH

Panda Virus Alert - Bagle.BC Red Alert Status

Panda Software Upgrades Security Threat to Red Alert Status as Bagle.BC Continues Causing Incidents Worldwide, New Variants, BD and BE, Have Appeared - Bagle.BC is spreading rapidly worldwide, causing more and more incidents, and now appears in the top half of the ranking of the viruses most frequently detected by Panda ActiveScan - Panda Software has made its free PQRemove utility available to all users to effectively detect and eliminate Bagle.BC from affected computers - Over the next few hours, thousands of emails infected by one of these worms will be circulating, and therefore the probability of a computer being infected is getting higher. New variants are also likely to emerge - TruPrevent Technologies, “the most intelligent technologies to combat unknown viruses and intruders,” Have effectively detected and blocked these 3 new variants of the Bagle worm, without needing to be able to identify them first Glendale, CA - October 29, 2004 - The Bagle.BC worm is increasing its already high rate of propagation, causing more and more incidents in users’ computers worldwide. Just a few hours after it appeared, it has made the top half of the ranking of the viruses most frequently detected by the online antivirus scanner, Panda ActiveScan. Even so, the number of incidents caused by this worm is expected to continue increasing and new variants are expected to emerge over the next few hours. This has prompted Panda Software to declare a Red Virus Alert as a preventive measure, so that all users can protect themselves against these worms and prevent their computers from being infected. Similarly, companies also risk their communications being slowed down by the large number of emails that mail servers will have to process. In addition to this worm, PandaLabs has detected the appearance of the two new variants, BD and BE, of the same worm. As with Bagle.BC, Panda Software clients that have already installed the new TruPrevent Technologies have preventive protection against these worms, as they were able to detect and block these new variants of the Bagle worm without needing to be able to identify them first (more information about the new TruPrevent Technologies at http://www.pandasoftware.com/truprevent). Panda Software has made the corresponding updates available to its clients to detect and disinfect these new worms. What’s more, it has made its free PQRemove utility available to all users to effectively detect and eliminate Bagle.BC from computers affected by this worm. Users can download this utility from the following address http://www.pandasoftware.com/download/utilities/ With the appearance of these new variants, the objective of the authors of these worms is obvious: release the maximum number of malicious code to increase the huge probability of computers being hit by one of them. According to Luis Corrons: “this is a technique that is being used more often. Virus creators know that the reaction time to new threats is critical, and therefore, the faster they can release various viruses, the easier it is for users to take too long to update their system. This problem is resolved with our TruPrevent Technologies, which have blocked these new worms without users needing to do a thing.” The new variants detected are very similar to Bagle.BC, a worm that spreads via email, networks and P2P applications like KaZaA. However, they do have some difference, such as the number of files they generate on the computers they infect. The three new Bagle worms share the fact that they have been designed to end the processes belonging to antivirus and security applications running in memory. However, none of these worms can affect the functioning of the TruPrevent Technologies. To prevent incidents involving the new variants of Bagle, Panda Software advises users to take precautions and to keep their antivirus software updated. Panda Software’s clients can already access the updates for installing the new TruPrevent Technologies along with their antivirus protection, providing a preventive layer of protection against these and other new malicious code. For users with a different antivirus program installed, Panda TruPrevent Personal is the perfect solution, as it is both compatible with and complements these products, providing a second layer of preventive protection that acts while the new virus is still being studied and the corresponding update is incorporated into traditional antivirus programs, decreasing the risk of infection. More information about TruPrevent Technologies at http://www.pandasoftware.com/truprevent For further information about Bagle.BC, Bagle.BD and Bagle.BE, visit Panda Software's Virus Encyclopedia at: http://www.pandasoftware.com/virus_info/encyclopedia/ In addition, users can scan their computers online for free with Panda ActiveScan, available at http://www.pandasoftware.com About PandaLabs On receiving a possibly infected file, Panda Software's technical staff get right to work. The file is analyzed and depending on the type, the action taken may include: disassembly, macro scanning, code analysis etc. If the file does in fact contain a new virus, the disinfection and detection routines are prepared and quickly distributed to users. For more information: http://www.pandasoftware.com/virus_info For more information: Alan Wallace [email protected]

Original source: panda-us-virusalert-2004-10-29-baglebc-redalert.doc