You are here: silicon.com > Software > Security Strategy

Security Strategy

Bugbear worm - how it works

And what to do about it

By CNET Networks

Published: 1 October 2002 08:40 BST

Bugbear arrives via email with no distinct characteristics except for an attached file that is always 50,688 bytes long. The subject line and text may be taken from existing email. Bugbear also arrives through network file sharing.

When run, Bugbear adds itself to the System subdirectory of the Windows folder as four random letters followed by .exe (for example, windows\System\zayb.exe). It also changes the Registry in order to run each time Windows is loaded, once again using random letters.

Finally, it adds itself to the Startup folder as three random letters followed by .exe (for example, Startup\zay.exe). The Trojan horse part of this worm first terminates many popular firewall and antivirus programs. The Trojan then launches a keystroke-logging program whose filename is a variable number of random letters followed by .dll (for example, avbxcydz.dll). Keystroke-logging programs memorize the keystrokes typed when filling out login information (passwords) or filling out shopping forms online (credit card information).

Files saved by these programs can later be accessed remotely by malicious users. The Trojan component of this worm opens port 36794.

Prevention
Users of Internet Explorer 6 should be safe from the email portion of this worm. Users of IE 5.01 and 5.5 who have not installed the Infected Mime header patch found in MS01-020 should do so. If you do not need to share files on a network, you should also turn off file sharing within Windows.

Removal
A few anti-virus software companies have updated their signature files to include this worm. This will stop the infection upon contact and in some cases will remove an active infection from your system.

Jeanne-Vida Douglas and Robert Vamosi write for ZDNet.com.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
HCM Business Transformation Consultant (Europe)

We have a great team of more than 3,000 human capital professionals who bring skills, competencies, knowledge sharing and experience to meet client ...

Data Coordinator Contract Research Organisation.

To assist in the creation of test data for validating data entry screens and data validation programs. To file study related documents To ...

Business Intelligence - Designer

Proactively identifying opportunities to improve and rationalise applications and processes across the whole BI team, working in close collaboration ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: