Bagle.B Worm Detection

high Nessus Plugin ID 12063

Language:

Synopsis

A worm was detected on the remote host.

Description

The remote host has the Bagle.B worm installed. This is a variant of the Bagle worm which spreads via email and has a backdoor that listens on port 8866.

Solution

Use an antivirus product to remove the worm.

See Also

http://www.nessus.org/u?ac5cd26f

Plugin Details

Severity: High

ID: 12063

File Name: bagel_b_detection.nasl

Version: 1.26

Type: remote

Family: Backdoors

Published: 2/17/2004

Updated: 11/25/2019

Asset Inventory: true

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C