VIRUS ALERT: Bugbear - Spreading Rapidly!! edit**now with removal tools**

guyver01

Lifer
Sep 25, 2000
22,135
5
61
SARC
SOPHOS
McAfee

Name: W32/Bugbear-A
Aliases: Tanat, Tanatos
Type: Win32 worm
Date: 30 September 2002


This worm emails itself to addresses found on the local system. Possible message subject lines include the following (however, other random subject lines are also possible):

Found
150 FREE Bonus!
25 merchants and rising
Announcement
bad news
CALL FOR INFORMATION!
click on this!
Correction of errors
Cows
Daily Email Reminder
empty account
fantastic
free shipping!
Get 8 FREE issues - no risk!
Get a FREE gift!
Greets!
Hello!
history screen
hotmail.
I need help about script
Interesting
Introduction
its easy
Just a reminder
Lost
Market Update Report
Membership Confirmation
My eBay ads
New bonus in your cash account
New Contests
new reading
News
Payment notices
Please Help
Report
SCAM alert
Sponsors needed
Stats
Today Only
Tools For Your Online Business
update
various
Warning!
Your Gift
Your News Alert

The message body and attachment name vary. It is common for the attachment name to contain a double-extension (ie. .doc.pif). Outgoing messages look to make use of the Incorrect MIME Header Can Cause IE to Execute E-mail Attachment vulnerability in Microsoft Internet Explorer (ver 5.01 or 5.5 without SP2).


Indications Of Infection:

Port 36974 open (verify thru netstat -an)

Existence of the following files (* represents any character):

%WinDir%\System\%random filename%.EXE (50,688 bytes)
%WinDir%\System\%random filename%.DLL
%WinDir%\System\%random filename%.DLL
%WinDir%\System\%random filename%.DLL
 

aphex

Moderator<br>All Things Apple
Moderator
Jul 19, 2001
38,572
2
91
Originally posted by: ThePresence
Someone give this man a sticky!

** aphexII begins to methodically st.....

Oooooo, you meant for the thread...
rolleye.gif
 

guyver01

Lifer
Sep 25, 2000
22,135
5
61
Originally posted by: aphexII
Originally posted by: ThePresence
Someone give this man a sticky!

** aphexII begins to methodically st.....

Oooooo, you meant for the thread...
rolleye.gif

:Q

i do NOT want to know what you thought he meant..
 
Jan 31, 2002
40,819
2
0
Where's the damned sticky on this?

Special notice - this will definitely fux0r campus students - all it takes is one airhead to run it, then it spreads over network shares. Oi.

- M4H
 

guyver01

Lifer
Sep 25, 2000
22,135
5
61
This is definitely a biggie... musta had 20 morons... er.... customers... call in tonight infected with this.

when will people learn!!

W32.Bugbear@mm is a mass-mailing worm. It can also spread through Network shares. It has backdoor capabilities.

It is written in Microsoft Visual C/C++ programming language and compressed with UPX.

UPDATE: Symantec has issued a liveupdate today, so Bugbear must be a significant threat!! Also, I just got this from McAfee Dispatch:

McAfee.com has seen a growing number of computers infected with W32/Bugbear@MM. The risk assessment has been updated to MEDIUM FOR HOME AND CORPORATE USERS.

Technical Details

Subject: variable; may well be based on an existing emails.
Text: variable; as above
Attachment: filename is variable, but always has the file size of 50688 bytes.

Virus Behaviour

The virus is a mass-mailing virus, which can propagate using the MIME-020 vulnerability. BugBear also appears to have the ability to disable or disarm AV software.

Payload

The virus appears to contain a key-logging Trojan. This potentially could be used to steal passwords and credit-card details.
 

Anubis

No Lifer
Aug 31, 2001
78,712
427
126
tbqhwy.com
yea this should be everywhere. i think our campus is still tryin to recover from nimda. cause peopel had it last year and didnt know it and they just pluged there comp back into the network here again and its started allover again.

main i hate people who dont know how to run Anti virus software that comes free with there comps. also updating windows wouldent hurt either. i ask peopel if they have done this and they look at me like im speakin a forgin language
 

Nitemare

Lifer
Feb 8, 2001
35,461
4
81
Originally posted by: TheEvil1
yea this should be everywhere. i think our campus is still tryin to recover from nimda. cause peopel had it last year and didnt know it and they just pluged there comp back into the network here again and its started allover again.

main i hate people who dont know how to run Anti virus software that comes free with there comps. also updating windows wouldent hurt either. i ask peopel if they have done this and they look at me like im speakin a forgin language


They should be written up on the first offense then fired on the second. Virus's only exist because of stupid people. The sooner they are taken cared of, removed from computers, educated or whatnot, the sooner virus's will go away.
 

Harvey

Administrator<br>Elite Member
Oct 9, 1999
35,057
67
91
Thanks. In case you didn't know it, for Norton AV users, in addition to Live Update, which they say is typically updated once a week, you can pick up any intermediary updates using Intelligent Update, which d/l's an EXE file containing the very latest virus definitions.
 

LakerGod

Platinum Member
May 19, 2001
2,477
0
0
Is Intelligent Updated an option in the AntiVirus program, or do you have to download it seperately?
 

mithrandir2001

Diamond Member
May 1, 2001
6,545
1
0
Originally posted by: OmegaNauce
Originally posted by: ndee
HAHA, Mandrake 9.0 here :)

i love it!
Nobody bothers Linux becuase nobody uses Linux for anything important. :p:p:p:p:p

I let Norton scan my drives. 99077 files. Damn, how did I accumulate so much stuff???
 

GoingUp

Lifer
Jul 31, 2002
16,720
1
71
I got the bugbear virus but it didn't get picked up by the latest version of nortons.....weird.....I scanned the file and everything...?