ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Bugbear rise knocks out Klez

Matthew Broersma ZDNet.co.uk

Published: 03 Oct 2002 16:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Bugbear worm is shaping up into the most serious Internet threat in months, according to security researchers, as it surpassed the lingering Klez.H to become the fastest-spreading virus of the moment. Antivirus company Symantec on Wednesday upgraded the virus to a danger rating of "4" out of a possible "5".

The rise of Bugbear to the top of the virus charts is partly due to the speed at which it is spreading, but also in part to an unexpected effect that it is having.

Email and security service provider MessageLabs intercepted more than 21,000 copies of the virus on Thursday, compared with nearly 6,000 copies of Klez.H, which has topped the virus charts sporadically since February. This is partly because of Bugbear's rapid rise, but MessageLabs said that in addition Klez activity has suddenly dropped to about a quarter of its usual levels.

"With all the publicity around Bugbear, people are finally getting around to updating their antivirus software, so Klez is suddenly falling," MessageLabs chief technical officer Mark Sunner told ZDNet UK. "Klez has been going forever and ever, and now it's been killed off."

Meanwhile, the company predicted that Bugbear has probably not peaked yet.

Threat of second-wave attacks
Sunner said that the virus' growing presence poses a new threat. Since Bugbear leaves a backdoor program on infected machines, there could now be thousands of computers around the world susceptible to further attacks. "All a hacker has to do is point a browser at that machine and they can get at everything on the hard disk," Sunner said. "Because Bugbear has received so much publicity, all the hackers will be riding onto this. There is a plethora of machines up for grabs."

Such vulnerable machines can be used, for example, to overwhelm a company's servers in what is called a distributed denial-of-service attack.

Known technically as W32.Bugbear or I-Worm.Tanatos, experts now believe the virus to be a modified version of the earlier Badtrans worm. Besides installing the backdoor, the worm disables various antivirus measures and any personal firewall that might be present, and installs a program for recording keystrokes -- which can log any passwords the user types in. It scours the computer for email addresses, to which it sends infected messages via its own email engine. The virus only affects Windows machines.

A flaw in MIME (the multipurpose Internet mail extensions) lets a malicious program attached to an email message execute when the text of the message appears in Outlook. The software problem was patched by Microsoft almost 18 months ago, but some users apparently have not updated their computers.

However, even with the patch, if a user clicks on the attachment he can still be infected.

Clever social engineering
One of the factors that has made Bugbear spread so quickly is the way it disguises infected messages. Besides the common method of sending a message with a randomly-selected heading and "From" field, the virus can also create a message as a reply or forward of an existing message.

"If you're receiving an old email from someone who you know, it's confusing, and you're likely to click on the attachment to find out what's going on," said Sunner. "It's a good social engineering trick."

The worm began infecting computers on Sunday, originating in the Asia-Pacific region, according to MessageLabs. That area is still its biggest concentration, and because the company has fewer customers in the region, there are probably many more uncounted viruses.

Security experts say that the biggest factor in the continuing danger from Bugbear, Klez.H and other worms is that users aren't bothering to update their virus protection -- and this is particularly true of home users.

Protection
Antivirus companies recommend that users download Microsoft's Outlook patch, update their antivirus programs and avoid clicking on mysterious attachments unless the sender confirms it is safe.

Eugene Kaspersky, head of Kaspersky Labs, recommends updating antivirus software weekly or daily, treating any email attachments with suspicion and paying attention to warnings from antivirus companies. "If you follow these rules, you will be 90 percent protected," he said in a recent interview with ZDNet UK.

For instructions on protecting your computer from Bugbear, see ZDNet UK's Help & HowTo: Bugbear.

For antivirus vendor instructions, see Central Command, F-Secure, McAfee, Sophos and Symantec.

CNET News.com's Robert Lemos contributed to this report.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
39 out of 74 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Support Engineer

Support and maintenance of the CSIS domain Software including: UNIX and Microsoft OS, SAN, Exchange, SQL and Antivirus software. Support Engineer - ...

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS,

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS, - Lambeth - 2198 RM helps to push the boundaries of technology to ...

Information Analyst Required with 18 Weeks & SQL Exposure - Merseyside

NHS datasets, ability to create pivot table, access queries and charts/graphs in Access/Excel. Rate is in the region of 140-200 per day, the role is ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains