Bagle.BB is a nasty one and Bagle.AZ just came out so keep an eye out for that as well. From what I understand, after an infection of any Bagle variant so far, TCP port 81 is opened to a high UDP port on a machine it tries to infect as well as sending emails out.
----------------------------
"Security is like an onion" - Unknown