ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Bugbear virus threat on the rise

Published: 02 Oct 2002 08:02 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new email virus gained a greater foothold in unpatched Windows PCs on Tuesday, spurring antivirus companies to upgrade their estimate of the virus' danger.

Known as W32.Bugbear or I-Worm.Tanatos, the mass-mailing computer virus started infecting computers via email on Sunday. On Tuesday, it accounted for nearly 11,000 infected email messages intercepted by email service provider MessageLabs' gateway servers. That placed it second to Klez.h, which accounted for about 14,000 email messages.

"It is so hard to stay up with all the patches," said John Harrington, US marketing director for MessageLabs. Harrington said most home users don't even realise they're missing a needed security fix.

The Bugbear virus infects computers running the Windows operating system and an unpatched version of Internet Explorer 5.5, according to an advisory posted by security company Symantec. A flaw in MIME (the multipurpose Internet mail extensions) lets a malicious program attached to an email message execute when the text of the message appears in Outlook. The software problem was patched by Microsoft almost 18 months ago, but some users apparently have not updated their computers.

Once running, Bugbear searches a PC for email addresses and uses its own email engine to send off infected messages to each address listed. In addition, it uses random email addresses in the "from" field of the header to camouflage where the infected message is coming from.

The virus also attempts to shut down a host of security programs and antivirus measures, including many personal firewall programs and most popular antivirus scanning engines.

Lastly, Bugbear sends off an encrypted file with information about the computer to a predefined email address and opens a backdoor for network attackers to use to sneak into the system.

Symantec upgraded the threat rating of the virus to a "3" on Tuesday from a "2" on Monday, with the most severe rating being a "5". The rating measures various factors including the destructiveness of a virus and how fast and how far the virus has spread.

To prevent infection, Windows users should download the Microsoft patch, update their antivirus software and refrain from opening an attachment unless the sender confirms he or she sent it.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
40 out of 63 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

McAffee Anti Virus Rollout Engineer CRB Cleared

The role will require the following - - Experienced in field support - Windows 2000 / XP / Vista - Anti - Virus experience For an immediate telephone ...

HRS - Operations Support Lead-00055714

Consolidate performance updates to power point document Management of contract review actions/progression/chasing/reporting/closing Maintenance of ...

IBM Websphere Message Broker- Flow Developer- ESQL JAVA

IBM Websphere Message Broker (WBIMB) Flow Developer (ESQL or JAVA) urgently required by my West Midlands client for a short term contract. You will ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal