Worm:W32/Bugbear

Your keyboard has one hour to another to duplicate the accents? This is when you press’ or ~ they come out duplicates? This is a symptom of the virus BugBear, which began to spread over the Internet on September 30.

The BugBear (also called Thanatos) is a virus e-mail with behavior similar to “famous” Klez. That is, when your machine is infected, it begins to send emails from your computer. The big problem is that, like Klez, it “spoofs” the sender, picking a random name from your list of emails. That way, when you receive an email with the virus, possibly the e-mail that is marked as the sender is not the person who is actually sending you the virus. So no point in answering the e-mail saying “your computer is virus.”

The biggest problem is that this virus is a “backdoor”, ie the infected machine as well as send e-mail viruses can be easily accessed by hackers, and your data is completely exposed.

The virus prevents you run an antivirus. If you are unable to open your antivirus, then it may mean that your machine is infected.

Remove viruses from your machine is relatively easy, just delete the files from the virus. The problem is that at the time of infection, the files are created with random names, and therefore we can not know the exact name of the files to be deleted. Anyway, there is the Internet a small utility to remove this virus, which can be downloaded for free at ftp://ftp.f-secure.com/anti-virus/tools/f-bugbr.zip. Just download, unzip with Winzip and run.

If your machine is networked, the virus attempts to spread the network as well. Therefore, if local networks, the entire network must be disconnected before moving antivirus on all machines, because otherwise, you can eliminate the virus from your machine, but if another PC is infected shortly after their PC will be infected again, via the network.

This worm exploits the same bug in Internet Explorer and Outlook that uses the Klez, which means that you do not need to run the attachment (the virus) of a message to your PC being infected. If you install a patch existing security on the Microsoft website at http://www.microsoft.com/windows/ie/downloads/critical/q323759ie/default.asp, your computer will be less vulnerable to viruses from e-mails.

After eliminating the virus completely from your machine, do not forget to update your antivirus.

Also, for security reasons, we recommend that you replace all your logins and passwords, because the virus harvests login information and password of your computer and send by e-mail and someone may receive such information and to misuse them.

For complete information on this virus, visit http://www.f-secure.com/v-descs/tanatos.shtml.

Symantec tool:

http://www.symantec.com/security_response/writeup.jsp?docid=2002-093007-2144-99&tabid=2

Deixe um comentário

O seu endereço de email não será publicado. Campos obrigatórios marcados com *