MegaHertz
10-04-2002, 11:41 AM
The Bugbear worm is shaping up into the most serious Internet threat in months, according to security researchers, as it surpassed the lingering Klez.H to become the fastest-spreading virus of the moment. Antivirus company Symantec on Wednesday upgraded the virus to a danger rating of "4" out of a possible "5". More... (http://msn.com.com/2100-1105-960696.html)
You can also read more about it here (http://www.nod32.com/msgs/bugbear.htm). This one looks like it is spreading fast so make sure your virus definitions are up to date! If you have been infected you can download this free cleaner (http://www.nod32.com/bb_cln_en.exe) from Eset software.
hayc59
10-04-2002, 11:56 AM
whoa.....thanks for this heads up!!:D
grey ghost
10-05-2002, 04:54 AM
Hi
here is a list of AV and firewalls it tries to terminate.
web32/Bugbear-A.
ZONEALARM.EXE, WFINDV32.EXE, WEBSCANX.EXE, VSSTAT.EXE, VSHWIN32.EXE, VSECOMR.EXE, VSCAN40.EXE, VETTRAY.EXE, VET95.EXE, TDS2-NT.EXE, TDS2-98.EXE, TCA.EXE, TBSCAN.EXE, SWEEP95.EXE, SPHINX.EXE, SMC.EXE, SERV95.EXE, SCRSCAN.EXE, SCANPM.EXE, SCAN95.EXE, SCAN32.EXE, SAFEWEB.EXE, RESCUE.EXE, RAV7WIN.EXE, RAV7.EXE, PERSFW.EXE, PCFWALLICON.EXE, PCCWIN98.EXE, PAVW.EXE, PAVSCHED.EXE, PAVCL.EXE, PADMIN.EXE, OUTPOST.EXE, NVC95.EXE, NUPGRADE.EXE, NORMIST.EXE, NMAIN.EXE, NISUM.EXE, NAVWNT.EXE, NAVW32.EXE, NAVNT.EXE, NAVLU32.EXE, NAVAPW32.EXE, N32SCANW.EXE, MPFTRAY.EXE, MOOLIVE.EXE, LUALL.EXE, LOOKOUT.EXE, LOCKDOWN2000.EXE, JEDI.EXE, IOMON98.EXE, IFACE.EXE, ICSUPPNT.EXE, ICSUPP95.EXE, ICMON.EXE, ICLOADNT.EXE, ICLOAD95.EXE, IBMAVSP.EXE, IBMASN.EXE, IAMSERV.EXE, IAMAPP.EXE, FRW.EXE, FPROT.EXE, FP-WIN.EXE, FINDVIRU.EXE, F-STOPW.EXE, F-PROT95.EXE, F-PROT.EXE, F-AGNT95.EXE, ESPWATCH.EXE, ESAFE.EXE, ECENGINE.EXE, DVP95_0.EXE, DVP95.EXE, CLEANER3.EXE, CLEANER.EXE, CLAW95CF.EXE, CLAW95.EXE, CFINET32.EXE, CFINET.EXE, CFIAUDIT.EXE, CFIADMIN.EXE, BLACKICE.EXE, BLACKD.EXE, AVWUPD32.EXE, AVWIN95.EXE, AVSCHED32.EXE, AVPUPD.EXE, AVPTC32.EXE, AVPM.EXE, AVPDOS32.EXE, AVPCC.EXE, AVP32.EXE, AVP.EXE, AVNT.EXE, AVKSERV.EXE, AVGCTRL.EXE, AVE32.EXE, AVCONSOL.EXE, AUTODOWN.EXE, APVXDWIN.EXE, ANTI-TROJAN.EXE, ACKWIN32.EXE, _AVPM.EXE, _AVPCC.EXE, _AVP32.EXE
regards
That puny thing was written in Microsoft Visual C++... doubt it will cause much alarm. :o
Danil
10-07-2002, 01:33 AM
Didn't notice Tauscan and Jammer in this list...
However both of them can be useful - Jammer will infomr the user that virus tries to change the registry, TauMonitor will let user to kill this process, so there will be no infection (according to the information from one of our users).
MegaHertz
10-15-2002, 05:04 AM
Unfortuneately Danil Outpost is. See attached.
RISC OS
10-15-2002, 05:34 AM
If someone had enabled password, and bugbear tried to kill Outpost would Outpost present the user with the password box or does BB kill programs in away that would get round the password protection for shutting down OP?
MegaHertz
10-15-2002, 06:01 AM
Hey Risc OS see this thread (http://www.outpostfirewall.com/forum/showthread.php?s=&threadid=5207). It may partially answer your question.
vBulletin® v3.8.4, Copyright ©2000-2010, Jelsoft Enterprises Ltd.