As of 4:15 PM (GMT -07:00) DST, TrendLabs declared a Medium alert to control the spread of this new BAGLE variant that is spreading via email and network shares. Initial infection reports has been received from the U.S. and Canada.

This worm utilizes SMTP (Simple Mail Transfer Protocol) to propagate via email.

This worm arrives via email and network shares. Upon execution, it drops copies of itself as the following files in the Windows system folder:


sysxp.exe
sysxp.exeopen
sysxp.exeopenopen

Bagle.AF by Trendmicro

Bagle.AF Secunia Advisory