»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Off Topic Community

Reply
 
LinkBack Thread Tools Display Modes
Old 10-01-2002, 07:13 AM   #1 (permalink)
Registered User
 
maface's Avatar
 
Join Date: Oct 2001
Location: MA
Posts: 1,154
maface is on a distinguished road
Bug Bear Virus

another virus

bug bear

maface is offline   Reply With Quote
Old 10-01-2002, 07:25 AM   #2 (permalink)
Registered User
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 2,211
nomaxim is on a distinguished road
Got my McAfee Alert and DAT update about two hrs. ago.

Med. risk to IE 5.01 and 5.5. W/O SP2.
That's why I stay with Netscape or Opera.

Looks like a Klez mutation, but it tries to disable A/V , and bypass firewalls.

Nasty

One possible subject line is: COWS ??

Last edited by nomaxim; 10-01-2002 at 07:30 AM.
nomaxim is offline   Reply With Quote
Old 10-01-2002, 08:20 AM   #3 (permalink)
mickwish
Guest
 
Posts: n/a
Nasty chappy, this bugbear. hers' waht one of my ISP's has to say in a warning email:
Quote:
Bugbear picks up a random old mail message from an infected
computer and re-sends it, impersonating the original sender, with a copy of
the worm attached. It does this in order to try to spread itself more
effectively, by pretending to come from someone that you already know.

*ISPname* has already seen some copies of this worm being sent, in which
the worm has happened to pick up an old *ISPname* customer bulletin from
a customer computer, and used that as the basis of its attempts
to spread itself.

If you happen to see such a message - it was not actually sent by *ISPname*.
The message was chosen at random from the mailbox of a computer that was
infected with this worm.
Kinda klez-like, as no-maxim pointed out.

Beware those who don't have a/v proggies installed and up-to-date.

Symantec have upgraded this threat today:
Quote:
Due to an increased rate of submissions, Symantec Security Response has upgraded this threat from a Category 2 to a Category 3 as of September 30, 2002.
http://securityresponse.symantec.com...ugbear@mm.html
Cheers
Mick
  Reply With Quote
Old 10-01-2002, 08:34 AM   #4 (permalink)
Registered User
 
OuTpaTienT's Avatar
 
Join Date: Oct 2001
Location: Bay Area, CA USA
Posts: 6,966
OuTpaTienT is on a distinguished road
Send a message via ICQ to OuTpaTienT
I don't.

I ain't scared of no stinkin' virus. Bring it on.
OuTpaTienT is offline   Reply With Quote
Old 10-01-2002, 08:51 AM   #5 (permalink)
Registered User
 
Creatures's Avatar
 
Join Date: Jul 2002
Location: Switzerland
Posts: 3,962
Creatures is on a distinguished road
Send a message via ICQ to Creatures
i dont use outlook express as my mail inbox so i hope i dont get this thing, i hate viruses, who are these people creating such stupid things

first use of my smiles

Creatures
__________________
___)
(
____)REATURES
Creatures is offline   Reply With Quote
Old 10-01-2002, 09:33 AM   #6 (permalink)
Registered User
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 2,211
nomaxim is on a distinguished road
McAfee gives origin as Malaysia.

McAfee Page

It will try to disable ZoneAlarm., BlackIce, AVG, to name a few.

Sends stuff to network printers too.

Last edited by nomaxim; 10-01-2002 at 09:41 AM.
nomaxim is offline   Reply With Quote
Old 10-01-2002, 12:34 PM   #7 (permalink)
Guest
Guest
 
Posts: n/a
Quote:
The Trojan horse part of this worm first terminates many popular firewall and antivirus programs. The Trojan then launches a keystroke-logging program whose filename is a variable number of random letters followed by .dll (for example, avbxcydz.dll). Keystroke-logging programs memorize the keystrokes typed when filling out login information (passwords) or filling out shopping forms online (credit card information). Files saved by these programs can later be accessed remotely by malicious users. The Trojan component of this worm opens port 36794.
nasty little thing! thanks for the heads up!! gotta keep an eye out on that port! hopefully we won't have the little kids out probing the hell out of everyones computers.
  Reply With Quote
Old 10-04-2002, 01:35 AM   #8 (permalink)
Registered User
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 2,211
nomaxim is on a distinguished road
This bug has now been upgraded to 'HIGH RISK' !!!

For both home and corp. user's.
nomaxim is offline   Reply With Quote
Old 10-04-2002, 04:28 AM   #9 (permalink)
mickwish
Guest
 
Posts: n/a
OuT, how do you and Goassamer avoid Klez and his pals? You don't need to open an attachment for these fellows, just reading an innocent looking email from your mum can do it. It spoofs senders and steals titles from real emails.

Probably already Klez has you in his clutches, OuT. Is your firewall on or don't you believe in those either?

Cheers
Mick the cautious
  Reply With Quote
Old 10-04-2002, 07:40 AM   #10 (permalink)
Registered User
 
Graham's Avatar
 
Join Date: Oct 2001
Location: Ipswich Suffolk UK
Posts: 1,110
Graham is on a distinguished road
I got an unsolicited mail yesterday, with an attachment

My Money.mny.scr

size 50.8 K

No virus found by the checker, but I am suspicious., think this could be it?


G
__________________
Nothing moves faster than goalposts.
Graham is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 08:28 PM.