Bugbear.B Worm Virus
Information and Removal Help
What is
BugBear.B worm and How Did I Get It?
Its email messages contain an exploit that allows attachments to automatically execute when the messages are viewed or even previewed in Microsoft Outlook and Outlook Express. The vulnerability exploit affects systems with unpatched Internet Explorer 5.01 and 5.5. Microsoft has released a patch for this exploit, however many systems are still not updated. You can read more information about this exploit and patch by visiting the Microsoft security bulletin Incorrect MIME Header Can Cause IE to Execute E-mail Attachment. The worm sends an email with the following characteristics: Subject can be any of the following:
Attachment: the worm uses filenames in the My Documents folder location, which have one of the following extensions:
The attachment contains a double file extension (such as Attachment.jpg.exe) using one of the following:
Also the filename can contain one of the following words:
File infections of local and network drives The worm can also infect the following programs on local and network drives:
The worm attempts to copy itself to networked shared drives and does not differentiate between shared drives or printers, so it will inadvertently copy itself as a printer job sending garbled data to network printers. Keylogger The worm
drops a keylogger as a randomly named DLL in the \Windows\System
folder. The file is 5,632 bytes in size and is detected as
PWS.Hooker.Trojan (according to Symantec). The worm creates additional
encrypted files in the Windows and \Windows\System folders with
randomly named filenames, with the extensions .dll or .dat. These files
store configuration information and encrypted keystrokes that the
keylogger records. The worm contains over 1000 targeted bank domains, likely as an attempt to steal passwords more efficiently. If the worm determines the default email address of the computer belongs to one of these domains, it enables auto-dialing in the registry by setting the following registry key. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "EnableAutodial"="0000001" Antivirus and Security Program Termination The worm attempts to terminate antivirus and security product programs that match the following names:
Backdoor vulnerability Lastly, the worm also opens a listening port on port 1080. A hacker can connect to this port and perform the following actions:
How to Clean/Delete the BugBear.B Worm? Since Bugbear.B is a blended virus threat, I would not recommend trying any simple manual removal of this virus. Instead, either click on the following link to download an automatic removal tool from Symantec or following the directions below to update and run an antivirus check on your system. For Automatic Removal of the BugBear.B worm, click on the following link Symantec BugBear.B Automatic Removal Program As an alternative to running the automatic removal tool, follow these steps to upgrade your antivirus software and run a thorough virus check of your system.
A good online virus scanner to use is Trend Micro's Housecall |
Tools for Removing Spyware, Adware, and Malware PC HELL Welchia (Dllhost.exe and SVCHost.exe) Worm Removal Uninstall Antivir Instructions How to Manually Run the Microsoft Malicious Software Removal Tool Bloodhound.Exploit.6 Virus Removal Backdoor SDBot.H Trojan Removal
|
| Recommended Software for PC Hell Visitors | |||||
![]() Start FREE Scan... |
FREE Registry
Scan! Clean, repair, and optimize your system with the leading and award-winning Registry Booster from Uniblue. Registry Booster is the safest and most trusted solution to clean and optimise your system, free it from registry errors and fragmented entries. Through Advanced Error Detection Technology, Registry Booster automatically identifies missing, corrupt, or invalid items in your Windows registry and dramatically enhances performance and general stability. |
![]() Start FREE Scan... |
FREE Performance Scan! Now, you can get a faster, cleaner, and safer PC within minutes - without being a Windows expert! SpeedUpMyPC automatically finds the best settings for your PC and carefully controls your system resources to give you the best performance. Easy to use, this award-winning utility has all the features you could ever need to clean up your system, monitor resources, and improve performance. |
![]() Start FREE Scan... |
Free Spyware Scan! |
![]() including Ad-Aware SE, Norton Antivirus, and Mozilla Firefox |
![]() Perfect Uninstaller |
![]() Spy Sweeper |
|
Search PCHELL.COM |
|
|