Forum Moderators: open

Message Too Old, No Replies

New Level 4 Virus

w32.bugbear.b@mm

         

Visit Thailand

9:47 am on Jun 6, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



There is a new and pretty dangerous virus circulating that Symantec say they discovered yesterday.

www.symantec.com/avcenter/venc/data/w32.bugbear.b@mm.html

I have not seen anything on this but it seems to be very widespread and level four is the same level of Klez.

Added in: We just found it on one machine but only after going through msconfig and ending all processes, start menu etc

The virus attempts to stop most AV progs from working

benihana

10:01 am on Jun 6, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



ive had about 5 copies of this today. fortunately recieved an emergency update warning yesterday and updated everyones machines. its beeen picked up by the AV software so as long as you tell people not to double click i think youll be ok

ncsuk

10:03 am on Jun 6, 2003 (gmt 0)

10+ Year Member



w32 = klez virus

Its not similar its exactly the same :)

ritch_b

10:04 am on Jun 6, 2003 (gmt 0)

10+ Year Member



We got updates from Sophos mid-yesterday - just in time to start receiving a barrage of suitably infected mails.

Never rains but it pours...

R.

Visit Thailand

10:11 am on Jun 6, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Its not similar its exactly the same :)

The Klex virus in April did not have keystoke recoding capability nor backdoor entry capability where the hacker could do pretty much anything he wanted including edning any processes deleting files etc.

But anyway all I know is it is a pain in the *** so in that way yes it is exactly the same.

Robert Charlton

4:48 pm on Jun 7, 2003 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



I don't know whether this is an indicator of bugbear or some other virus, but it is an indicator... If you can view email headers on the server before downloading, a file size of 99K seems to accompany at least one payload that's going around.