Forum Home
Press F1
 
Thread ID: 25341 2002-10-01 11:27:00 More on Bugbear Jim B (153) Press F1
Post ID Timestamp Content User
85098 2002-10-01 11:27:00 Bugbear attempts to steal passwords and credit card information

From ZDNet ( news.zdnet.co.uk)

The Trojan horse part of this worm first terminates many popular firewall and antivirus programs. The Trojan then launches a keystroke-logging program whose filename is a variable number of random letters followed by .dll (for example, avbxcydz.dll). Keystroke-logging programs memorize the keystrokes typed when filling out login information (passwords) or filling out shopping forms online (credit card information). Files saved by these programs can later be accessed remotely by malicious users. The Trojan component of this worm opens port 36794.

Prevention
Users of Internet Explorer 6 should be safe from the e-mail portion of this worm. Users of IE 5.01 and 5.5 who have not installed the Infected Mime header patch found in MS01-020 should do so. If you do not need to share files on a network, you should also turn off file sharing within Windows.


Also watch out for this hoax email which is in fact a virus.

A virus posing as a security patch from Microsoft Corp. is circulating on the Internet, Microsoft confirmed Monday.
Jim B (153)
1