Forum Home
Press F1
 
Thread ID: 25380 2002-10-02 09:48:00 BugBear - Virus/Trojan Vince (406) Press F1
Post ID Timestamp Content User
85399 2002-10-02 09:48:00 First identified 1400 GMT Monday. This beast spreads like a virus, via email; then collects passwords and credit card details to send out. Go here <www.newscientist.com for more info. Vince Vince (406)
85400 2002-10-02 10:39:00 Where were you yesterday Vince, considerable amount of info and discussion on previous posts. Jim B (153)
85401 2002-10-02 14:30:00 Lets keep our whits about us!

In flew the first one, without a blink from NAV.....


text=
>Hi Listers,I am looking for JOHN WILLETT and wife ELIZABETH living in Hugglescote or Donnington, listed as a coalminer on the 1881 census. Any info greatly appreciated. Thanks to all in advance,

>Sally Mcdonald

And the attachment?
Norton antivirus report -1.txt_presentation broshure.wps.exe
Chris Wilson (431)
85402 2002-10-02 14:45:00 And in flies another one, on a different address......
This makes Klez look like kindergarden!
Chris Wilson (431)
85403 2002-10-03 03:07:00 Hi Guys, i missed the discussion on this day before yesterday - but read this post last night, so really appreciated seeing this post. Question: I have just been told by a good friend that she has just got it (she is with xtra i.s.p too and had read that would help protect her- no such luck) - anyway she rang to warn me, which was great! Now i have just run NAV liveupdate and made sure i am up to date - Anything else i can do before i check my e-mail (to be honest after all this time of having a puter i have never actually had a scare, so I am really hoping everything will work how its supposed too!!) Do I just delete it when i see it come in??? Or will NAV 2002 pick it up before that??? Any advice would be great as, as i said luckily i have never experienced this before so hopefully being pre warned i can get it right!!
By the way my friend who has it - using win ME, cannot even start her computer it just says can't find windows system exe to load i think she said then it shuts down??? And she tried safe mode too gets her no further ??
J ZEP (336)
85404 2002-10-03 03:44:00 If using OeX, and an email with an attachment opens automatically, select "Cancel" you dont wanna do anything. Click on the Paperclip Icon and you'll see a list of attachments, if the filesize is 50.8KB, Delete it, It'll be the BugBear virus!

BTW, Dont try updating after you're infected, it'll be too late with norton, it kills it every 30 seconds. You'd need to goto:
http://www.grisoft.com and get AVG - AntiVirus General

Just be careful! My parents got infected yesterday and was a pain in the @$$ to clean up!

Luckily my work PC is fine, and my linux box at home... which still isn't networked.. :(

Cheers

Chilling_Silence
Chilling_Silence (9)
85405 2002-10-03 03:52:00 Symantec have a removal tool,
here (securityresponse.symantec.com)
It would be worth getting this and running it as a precaution.
Terry Porritt (14)
85406 2002-10-03 04:03:00 After all the publicity and information in recent times about the danger of opening attachments people still do it.
What is it going to take to get it through to these people.
These virus emails are easy to identify so why tempt fate and open them.

Relying on ISP virus removal is a big mistake, they can slip through this just as they can get through your own anti-virus software if it is not updated.

The ultimate responsibility rests with the end user, even if your ISP has a virus filter it is still essential to have an updated AV program installed on your computer.

The best safeguard of all NEVER open attachments especially those with .exe .scr .pif file extensions.
Jim B (153)
85407 2002-10-03 04:07:00 Thanks for your help on this. One man uers like me really appreciate being able to find the right resources JohnPearce JohnPearce (2114)
85408 2002-10-03 04:24:00 Terry - I found that too, but if they were to scan using AVG, restarting after installa as told, it fixes it automatically.

OeX users - Try disabling the Preview Pane, Having that enabled, when selecting an email, you are effectively opening it and the attachments, which is why it pops up asking you to download the bugbear virus immediately. I have disabled it so that any message can be selected for deleting without opening the attachments. To do this yourself, Goto:
- View
- Layout

And uncheck "Preview Pane" which will subsequently grey-out two other options. To read a message, you have to double click on it to open.
Just noet, this isn't for everybody, but if you dont mind having to double click, by all means, feel free to remove the preview pane

Cheers

Chilling_Silence
Chilling_Silence (9)
1 2 3 4