Virus Profile: W32/Bagle!eml.gen

Threat Search
Virus Profile information details
Risk Assessment: Home Low | Corporate Low
Date Discovered: 7/21/2004
Date Added: 7/21/2004
Origin: Unknown
Length: N/A
Type: Virus
Subtype: Generic
DAT Required: 4380
Removal Instructions


This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Indication of Infection

Methods of Infection


Virus Characteristics

This is a generic detection of email messages generated by various W32/Bagle@MM virus variants.  Since the detection is generic, it is not possible to state specific details in this description.

Please note: As this is a detection of the mail message itself, using specific identifiers about the mail message that are unique to the Bagle virus' email sending component, it is possible for this to trigger on email messages which have had the active viral component removed.

Additionally, because this is a detection of the mail message "as sent by the virus", if the message has been forwarded or "bounced" by an email system en-route to the recipient, it is possible for some samples which have had the virus attachment removed to be missed under some circumstances. Note: in these cases where this detection is missed, there will not be any active code if it's a known variant of W32/Bagle.

Customers should simply delete all email messages identified as W32/Bagle!eml.gen


All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).


PC Infected? Get Expert Help

Virus Removal Service

Connect to one of our Security Experts by phone. Have your PC fixed remotely - while you watch!