Here is what i'm talking about:

Symantec (Alua): http://[email protected]

Trendmicro (Bagle.B): http://www.trendmicro.com/vinfo/viru...e=WORM_BAGLE.B

Bitdefender: http://www.bitdefender.com/bd/site/v..._id=1&v_id=193


...........


Now... the links that are contacted when infected are:

www.strato.de/1.php
www.strato.de/2.php
www.47df.de/wbboard/1.php
www.intern.games-ring.de/2.php


/edit:

But I checked them from a linux machine and here are the results:

--12:09:00-- http://www.strato.de/1.php
=> `1.php'
Resolving www.strato.de... done.
Connecting to www.strato.de[192.67.198.33]:80... connected.
HTTP request sent, awaiting response... 404 Not Found
12:09:00 ERROR 404: Not Found.

--12:09:00-- http://www.strato.de/2.php
=> `2.php'
Resolving www.strato.de... done.
Connecting to www.strato.de[192.67.198.33]:80... connected.
HTTP request sent, awaiting response... 404 Not Found
12:09:01 ERROR 404: Not Found.

--12:09:01-- http://www.47df.de/wbboard/1.php
=> `1.php'
Resolving www.47df.de... done.
Connecting to www.47df.de[0.0.0.0]:80... failed: Connection refused.
--12:09:01-- http://www.intern.games-ring.de/2.php
=> `2.php'
Resolving www.intern.games-ring.de... done.
Connecting to www.intern.games-ring.de[217.160.214.166]:80... connected.
HTTP request sent, awaiting response... 404 Not Found
12:09:01 ERROR 404: Not Found.


Strange dns resolving though... 0.0.0.0 and 192.67.198.33


Anyways,

There you go,

Roach4