NEW: Bagle-AU worm disables Windows XP SP2 firewall
Experts at Sophos have warned users that the new W32/Bagle-AU worm attempts to disable security software on infected Windows PCs.
"By turning off firewall protection and other security software the author of the latest incarnation of the Bagle worm is opening up computers to attack," said Graham Cluley, senior technology consultant for Sophos. "Increasingly virus writers are aiming to take over innocent peoples' computers in order to steal, spam or cause mischief."
Sophos notes that the W32/Bagle-AU worm is capable of turning off the firewall built into Microsoft's recent Windows XP Service Pack 2 update.
"Just because you are running the latest version of Windows XP you shouldn't think you are necessarily protected from this worm," continued Cluley. "If you launch it on a PC running Windows XP SP2 it can turn off your firewall opening the door to hackers and other internet attacks."
News source: Sophos
adding old HDD to new compy for old info...and viruses...Doh!
I went and did it this time...
my old compy's power supply failed, and I was unable to find a new PS, so I bought a new compy...now, months later, I want the old information off the old HDD. so, I add it on as a slave...
...something twitches in the back of my head...old viruses...
So, I begin a barrage of scanning tools, AVG, Trend Micro, Ad-Aware...
and, of course, the HDD is choc-full of the bagle virus. AVG shows as follows: I-worm/bagle.ab, I-worm/bagle.ac, Trojan Horse Proxy.4.ap, and Trojan Horse Downloader.keenval.b
mostly bagle.ab.
any help on how to remove these from the drive? I'm downloading norton 05 trialware (Gotta love full-functioning trialware...) and I'm gonna see if it will fully remove it.
AVG says that it has healed them, but they keep coming back. GRR! I know I can always wipe the drive, but I have good information...and also my Everquest game (with expansions) on that drive... ANY help would be AWESOME.
btw - I could not find the win.32/bagle cleaner on Tech-Z's posted link.