Bugbear virus shows its claws

By Robert Lemos, CNET News.com
Friday, October 04, 2002 10:34 AM
The Bugbear virus continued to spread, spurring several antivirus software makers to raise their estimates of the program's danger for the second time this week.

Security software maker Symantec increased on Wednesday its rating of the virus to a 4 out of 5, while rival firm Network Associates bumped up its estimate of the infectious program on Thursday to a high danger from a medium.

"It doesn't show any sign of slowing down right now," said Craig Schmugar, virus research engineer for Network Associates' McAfee antivirus emergency response team on Thursday. "We have seen 50 to 60 percent more submissions today than yesterday."

Also known as Tanatos, the mass-mailing Bugbear computer virus can automatically infect Windows systems whose users haven't patched an 18-month-old flaw in Internet Explorer. PC users who have plugged the security hole still have to be careful--even if an automatic attack is blocked, opening the attachment will still allow the virus to infect a computer.

The virus copies itself to the hard drive of the victim's PC as well as to any other computers that share their drives over a network to which the infected system is attached.

Once in place, the computer virus stops a variety of security and antivirus programs from running. It also searches for e-mail addresses and sends itself as an e-mail attachment to every address that it finds. In addition, Bugbear opens up a "backdoor" on the computer through which an Internet attack can sneak into the system, and records everything a user types in certain windows, such as those for entering passwords. It occasionally sends off the file containing the keystrokes to several e-mail addresses.

Bugbear borrows many pages from the playbook of another successful virus, Klez.h. That virus has been the most prevalent computer virus for the past 6 months, according to data from e-mail service provider MessageLabs.

Part of Bugbear's success is due to its using its own e-mail engine to send off infected messages. As a result, the infected messages it sends contain a random e-mail address in the header's "from" field. This can camouflage, to some degree, the e-mail's source, which makes it difficult to determine whose computer sent the infected message. Identifying the infected computer, therefore, is that much more difficult.

The tactic has been so effective that Bugbear created more than 200,000 e-mail messages seen by MessageLabs' gateway in the last 24 hours, far outpacing the almost 60,000 messages created by Klez.h.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Output local group membership on Windows Server

Windows Server

Command line skills for Windows Servers are essential to deliver information without wasting time. Here's how an old tool and a new tool can help.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except that..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web