Need help? Ask the community or hire an expert.
Go to Avira Answers
Alias:W32.Alua@mm
Type:Worm 
Size:11,264 bytes (UPX) 
Origin:unknown 
Date:02-17-2004 
Damage:Sends emails using its own smtp engine 
VDF Version:6.24.00.07 
Danger:Low 
Distribution:Medium 

General DescriptionWorm/Bagle.B has a file size of 11.264 bytes and is packed with UPX. It copies itself in the Windows system folder with the file name AU.EXE and scans files on local non removable disks for email addresses, to which it sends itself with the help of its own smtp engines.

Symptoms* Increased email traffic.

Distribution* Sends emails using its own smtp engine

Technical DetailsWorm/Bagle.B sends itself by email with the help of its own smtp engine. The generated email has the following characteristics:

* Subject:
ID <%random characters%> ... thanks

Body:
Yours <%random characters%>
--
Thank

Attachment:
<%random characters%>.exe

If the attachment of the Worm/Bagle.B is executed, it copies into the Windows system folder as AU.EXE and creates the following registry entry:

* [HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\run]
au.exe = %SystemDIR%\au.exe

Worm/Bagle.B scans the files with the extensions html, htm, wab and txt on the local non removable disks for email addresses.

W32.Beagle.B@mm is coded to stop at the end of February 25, 2004.

Manual Remove Instructions- for Windows 2000/XP:
In order to remove the virus by hand, you should be in Safe Mode first. Press the F8 key when you start your computer, and select the 'safe mode' option that will appear. Delete the following files:

* \%WinDIR%\%SystemDIR%\AU.EXE

Start "regedit" after that and delete the following registry entries:

* [HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\run]
au.exe = %SystemDIR%\au.exe

Restart your computer.

- for Windows 9x/Me:
In order to remove the virus by hand, you should be in Safe Mode first. Press the F8 key when you start your computer, and select the 'safe mode' option that will appear. Delete the following files:

* \%WinDIR%\%SystemDIR%\AU.EXE

Start "regedit" after that and delete the following registry entries:

* [HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\run]
au.exe = %SystemDIR%\au.exe

Restart your computer.
Description inserted by Crony Walker on Tuesday, June 15, 2004

Back . . . .