Alerts
Posted: Sun Sep 05, 2004 8:22 pm
W32.Bugbear.M@mm
Discovered on: September 03, 2004
Last Updated on: September 04, 2004 12:43:28 PM
W32.Bugbear.M@mm is a mass-mailing worm that sends itself to email addresses it gathers from certain files on the system, using its own SMTP engine.
Variants: W32.Bugbear@mm
Type: Virus, Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX
Technical Details:
When W32.Bugbear.M@mm runs, it does the following:
Creates the following files:
%System%\<random filename>.nls
%System%\<random filename>.dat
%System%\<random filename>.tmp
%System%\<random filename>.dll
%System%\<random filename>.exe
Attempts to add the value:
"<random value>" = "%System%\<random filename>.exe"
in the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm starts when Windows starts.
Attempts to append its code to the following files in the %Windir% folder and %ProgramFiles% folder:
scandskw.exe
regedit.exe
mplayer.exe
hh.exe
notepad.exe
winhelp.exe
Internet Explorer\iexplore.exe
adobe\acrobat 7.0\reader\acrord32.exe
WinRAR\WinRAR.exe
Windows Media Player\mplayer2.exe
Real\RealPlayer\realplay.exe
Outlook Express\msimn.exe
Far\Far.exe
CuteFTP\cutftp32.exe
Adobe\Acrobat 6.0\Reader\AcroRd32.exe
Adobe\Acrobat 5.0\Reader\AcroRd32.exe
Adobe\Acrobat 4.0\Reader\AcroRd32.exe
ACDSee32\ACDSee32.exe
MSN Messenger\msnmsgr.exe
WS_FTP\WS_FTP95.exe
QuickTime\QuickTimePlayer.exe
StreamCast\Morpheus\Morpheus.exe
Zone Labs\ZoneAlarm\ZoneAlarm.exe
Trillian\Trillian.exe
Lavasoft\Ad-aware 6\Ad-aware.exe
AIM95\aim.exe
Winamp\winamp.exe
DAP\DAP.exe
ICQ\Icq.exe
kazaa\kazaa.exe
winzip\winzip32.exe
The worm is a polymorphic file infector.
Note:
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
%ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.
Scans all hard disks for files with file paths containing any of the following strings:
BEAR
DONKEY
DOWNLOAD
FTP
HTDOCS
HTTP
MORPHEUS
ICQ
KAZAA
LIME
MULE
INCOMING
SHAR
UPLOAD
If a file within these folders contains files with an .exe extension, the worm will attempt to infect those files.
Otherwise, it will copy itself as <original filename.ext>.exe (where .ext is the original file's extension).
Gathers email address from files whose filename contains any of the following strings:
.dbx
.tbb
.eml
.mbx
.nch
.mmf
Inbox
.ods
.htm
.asp
.txt
.sht
Uses its own SMTP engine to email itself to the email addresses that it collects.
The email has the following characteristics:
Subject: Starts with "Re: "
Attachment:
The worm searches for a specific folder by querying the following registry value:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell\Folders\Personal
Once the worm locates the name of the folder, it looks for a file that does not have a .INI, .ini, .rdp extentions. The worm uses the filename and then changes the file extension to .jpg and uses it as an attachment of the email.
Otherwise, the attachment may be one of the following:
a000032.jpg.scr
song.wav.scr
music.mp3.scr
video.avi.scr
photo.jpg.scr
pic.jpg.scr
message.txt.scr
image.jpg.scr
news.doc.scr
myphoto.jpg.scr
you.jpg.scr
love.jpg.scr
readme.txt.scr
Locates the following information from the infected computer and sends it to the attacker:
Cookies
Clipboard contents
Logged keystrokes
Text from open windows
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan, delete or repair all the files detected as W32.Bugbear.M@mm.
Reverse the changes made to the registry.
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
In the right pane, delete the value:
"<random value>" = "%System%\<random filename>.exe"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbear.m@mm.html\"]source[/url]
Discovered on: September 03, 2004
Last Updated on: September 04, 2004 12:43:28 PM
W32.Bugbear.M@mm is a mass-mailing worm that sends itself to email addresses it gathers from certain files on the system, using its own SMTP engine.
Variants: W32.Bugbear@mm
Type: Virus, Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX
Technical Details:
When W32.Bugbear.M@mm runs, it does the following:
Creates the following files:
%System%\<random filename>.nls
%System%\<random filename>.dat
%System%\<random filename>.tmp
%System%\<random filename>.dll
%System%\<random filename>.exe
Attempts to add the value:
"<random value>" = "%System%\<random filename>.exe"
in the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm starts when Windows starts.
Attempts to append its code to the following files in the %Windir% folder and %ProgramFiles% folder:
scandskw.exe
regedit.exe
mplayer.exe
hh.exe
notepad.exe
winhelp.exe
Internet Explorer\iexplore.exe
adobe\acrobat 7.0\reader\acrord32.exe
WinRAR\WinRAR.exe
Windows Media Player\mplayer2.exe
Real\RealPlayer\realplay.exe
Outlook Express\msimn.exe
Far\Far.exe
CuteFTP\cutftp32.exe
Adobe\Acrobat 6.0\Reader\AcroRd32.exe
Adobe\Acrobat 5.0\Reader\AcroRd32.exe
Adobe\Acrobat 4.0\Reader\AcroRd32.exe
ACDSee32\ACDSee32.exe
MSN Messenger\msnmsgr.exe
WS_FTP\WS_FTP95.exe
QuickTime\QuickTimePlayer.exe
StreamCast\Morpheus\Morpheus.exe
Zone Labs\ZoneAlarm\ZoneAlarm.exe
Trillian\Trillian.exe
Lavasoft\Ad-aware 6\Ad-aware.exe
AIM95\aim.exe
Winamp\winamp.exe
DAP\DAP.exe
ICQ\Icq.exe
kazaa\kazaa.exe
winzip\winzip32.exe
The worm is a polymorphic file infector.
Note:
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
%ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.
Scans all hard disks for files with file paths containing any of the following strings:
BEAR
DONKEY
DOWNLOAD
FTP
HTDOCS
HTTP
MORPHEUS
ICQ
KAZAA
LIME
MULE
INCOMING
SHAR
UPLOAD
If a file within these folders contains files with an .exe extension, the worm will attempt to infect those files.
Otherwise, it will copy itself as <original filename.ext>.exe (where .ext is the original file's extension).
Gathers email address from files whose filename contains any of the following strings:
.dbx
.tbb
.eml
.mbx
.nch
.mmf
Inbox
.ods
.htm
.asp
.txt
.sht
Uses its own SMTP engine to email itself to the email addresses that it collects.
The email has the following characteristics:
Subject: Starts with "Re: "
Attachment:
The worm searches for a specific folder by querying the following registry value:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell\Folders\Personal
Once the worm locates the name of the folder, it looks for a file that does not have a .INI, .ini, .rdp extentions. The worm uses the filename and then changes the file extension to .jpg and uses it as an attachment of the email.
Otherwise, the attachment may be one of the following:
a000032.jpg.scr
song.wav.scr
music.mp3.scr
video.avi.scr
photo.jpg.scr
pic.jpg.scr
message.txt.scr
image.jpg.scr
news.doc.scr
myphoto.jpg.scr
you.jpg.scr
love.jpg.scr
readme.txt.scr
Locates the following information from the infected computer and sends it to the attacker:
Cookies
Clipboard contents
Logged keystrokes
Text from open windows
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Restart the computer in Safe mode or VGA mode.
Run a full system scan, delete or repair all the files detected as W32.Bugbear.M@mm.
Reverse the changes made to the registry.
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
In the right pane, delete the value:
"<random value>" = "%System%\<random filename>.exe"
Exit the Registry Editor.
Restart the computer in Normal mode.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbear.m@mm.html\"]source[/url]