Gossamer Forum
Home : General : Internet Technologies :

EMERGENCY ALERT: W32/Bugbear-A spreading rapidly

Quote Reply
EMERGENCY ALERT: W32/Bugbear-A spreading rapidly
Just recieved the following email from my anti virus vendor:

EMERGENCY ALERT: W32/Bugbear-A spreading rapidly

Sophos has received several reports in a short space of time of users
receiving an email-aware worm called W32/Bugbear-A.
W32/Bugbear-A is an internet worm which spreads via SMTP and also attempts to spread via network shares. The worm copies itself to the Windows system folder as a file with a random four-letter name and an EXE extension and adds to the following registry entry to run this file on the next reboot:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

W32/Bugbear-A also drops a copy of itself in the Windows start up folder so that is run on system restart.

The worm drops a randomly-named DLL file, which is related to logging keystrokes, in the Windows system folder. It can also terminate certain firewall and antivirus programs.

A more detailed analysis of W32/Bugbear-A will be published here shortly. Please check again later.

- wil
Quote Reply
Re: [Wil] EMERGENCY ALERT: W32/Bugbear-A spreading rapidly In reply to
Somebody should make a virus that wipes out windows and installs redhat or even BeOs. Wink

openoffice + gimp + sketch ... Smile
Quote Reply
Re: [QooQ] EMERGENCY ALERT: W32/Bugbear-A spreading rapidly In reply to
LOL. Have you tried RedHat 8? I was going to install it onto our fileserver here, but decided against and upgraded Debian to sarge instead. Mmm. :-)

- wil
Quote Reply
Re: [Wil] EMERGENCY ALERT: W32/Bugbear-A spreading rapidly In reply to
nah, I don't have a pc box anymore.
Although, I've read that it's finally a release that comes to closer to Apple's simplisity.
Which is good for those who want to wet their feet with a Linux system.

I'm on BSD 4.4 essentially.

openoffice + gimp + sketch ... Smile