R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Bugbear virus on the loose

New worm disables security software

Iain Thomson, vnunet.com 01 Oct 2002
ADVERTISEMENT

A worm which disables security software and can steal passwords and credit card details is spreading rapidly through Windows-based PCs, according to antivirus companies.

Codenamed Bugbear, the worm was first detected in Malaysia and is spreading fast.

Network Associates' Anti-Virus Emergency Response Team identified the worm on 29 September and has upgraded its threat rating from 'low' to 'medium'.

Antivirus company MessageLabs has reported 6,000 infections in the UK, US and India.

The worm copies itself into the Windows system directory and start-up folder as a .exe file with a random three letter name.

Once installed it disables antivirus and firewall software and installs a Trojan keystroke logger as a DLL, detected as PWS-Hooker.dll.

Whatever the PC user types via the keyboard, such as passwords or sensitive information, is sent to the originator of the virus via the TCP port 36794.

The worm also seeks to infect all other PCs on the network via the address book and network shares.

In addition it takes advantage of a longstanding Microsoft exploit, MS-01/020, as did Klez. A patch for this has been available since March 2001.

"It beggars belief that this exploit is still being used," said Mark Toshack, virus analyst at MessageLabs.

"While this worm is new, the vulnerabilities it exploits are not. Home users must shoulder much of the blame for not updating their systems."

The infected emails are headed by a variety of greetings intended to trick users into allowing them into their own computers. It is common for the infected attachment name to contain a double-extension such as doc.pif.

The worm only affects Windows PCs and a patch is available from antivirus vendors.

See also:

The latest worm to sweep the globe carries a nasty payload, but fixes were available within hours. So why did it spread?  08 Oct 2002
Networked devices spewing out pages of binary code  07 Oct 2002
Hackers eye virus as base for development  24 Sep 2002
The evolution of hacking  20 Sep 2002
Users advised to hold off on Microsoft's next SQL Server  18 Sep 2002

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Technical Specialist Infrastructure - Welwyn Garden City Who's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at ... more >
Hertfordshire, United Kingdom | Tesco.com
Senior Business Analyst - Hertfordshire Who's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at just under ... more >
Solihull, United Kingdom | Enzen Global Limited
 BUSINESS CONSULTANT - Utilities - £35,000 - £40,000 - Solihull We are in need of a Business Consultant with strong analytical skills and a penchant for learning the domain knowledge of the Utilities sector (Gas ... more >
Shinfield Park, Reading, United Kingdom | Foster Wheeler
Our UK-headquartered operations employ more than 6,000 people and we are seeking qualified and experienced IT professionals to work in our head office in Reading, Berkshire. We are currently seeking an Analyst Programmer to join ... more >
More job opportunities