Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

How do you know if you've got BugBear virus?

Thread Tools
 
Search this Thread
 
Old 11 October 2002, 04:48 PM
  #1  
ScoobyDoo555
Scooby Regular
Thread Starter
 
ScoobyDoo555's Avatar
 
Join Date: Oct 2000
Location: Does it matter?
Posts: 11,217
Likes: 0
Received 0 Likes on 0 Posts
Question

Don't think I've got it, but just being a bit wary...

What are the symtpoms etc?

Is it wirth running the bugbear antidote (from Norton) just in case, or will it screw up my PC?

TIV

Dan
Old 11 October 2002, 04:55 PM
  #2  
Fuzz
Scooby Regular
 
Fuzz's Avatar
 
Join Date: Jul 2002
Location: Under your bonnet
Posts: 9,173
Likes: 0
Received 0 Likes on 0 Posts
Post

one would assume searching for the file "fwi acc details.t.exe" would do the trick.

Andy
Old 11 October 2002, 04:57 PM
  #3  
MarkO
Scooby Regular
 
MarkO's Avatar
 
Join Date: Oct 1998
Location: London
Posts: 4,891
Likes: 0
Received 0 Likes on 0 Posts
Cool

Take a look at http://vil.nai.com/vil/content/v_99728.htm. It's got a link to a remover, too.
Old 11 October 2002, 05:03 PM
  #4  
suba
Scooby Regular
 
suba's Avatar
 
Join Date: Mar 2000
Posts: 2,462
Likes: 0
Received 0 Likes on 0 Posts
Post

link is here
Old 11 October 2002, 05:04 PM
  #5  
DavidLewis
Scooby Regular
 
DavidLewis's Avatar
 
Join Date: Apr 1998
Posts: 1,864
Likes: 0
Received 0 Likes on 0 Posts
Post

Fuzz, I'm not sure but the attached file in the affected eMail can be called almost anything. One of mine was called OldExcelDocuments.lnk.pif for instance
Old 11 October 2002, 05:14 PM
  #6  
DavidLewis
Scooby Regular
 
DavidLewis's Avatar
 
Join Date: Apr 1998
Posts: 1,864
Likes: 0
Received 0 Likes on 0 Posts
Post

For those that haven't checked it out yet....

The symptoms are

Port 36794 TCP open
Existence of the following files (* represents any character):
%WinDir%\System\****.EXE (50,688 or 50,684 bytes)
%WinDir%\******.DAT
%WinDir%\******.DAT
%WinDir%\System\******.DLL
%WinDir%\System\*******.DLL
%WinDir%\System\*******.DLL
Large Print jobs sent to network printers. The full printout caused by a copy of the worm in the printer queue can take about 500 pages. They are mostly blank with only one-two lines of random symbols on each page. The very first page starts with "MZ" followed by about 18 funny symbols and a string "=!This program cannot be run in DOS mode". Another visible printed string close to the beginning is "Rich5".

Old 11 October 2002, 06:37 PM
  #7  
Fuzz
Scooby Regular
 
Fuzz's Avatar
 
Join Date: Jul 2002
Location: Under your bonnet
Posts: 9,173
Likes: 0
Received 0 Likes on 0 Posts
Post

I stand corrected, thanks dave
Don't know much about these things.. only got mine today..virus that is..not the pc

Andy
Old 11 October 2002, 07:41 PM
  #8  
AndiThompson
Scooby Regular
 
AndiThompson's Avatar
 
Join Date: Aug 2001
Location: Republic Of Mancunia
Posts: 2,474
Likes: 0
Received 0 Likes on 0 Posts
Post

I've had it. E-Mail wasnt working on of the PCs at work, went to see, and was totally baffled. Whilst checking the normal stuff, noticed Norton wasnt running. So I started it, and a few seconds later, it closed itself, repeat 2 or 3 times before I got suspicious and checked the symantec site.

Recieved it in e-mail 5 times now, and all 5 were from computery related websites, most from aspsql.com and one from someone claiming to be something to do with internic.
Old 12 October 2002, 10:14 PM
  #9  
SiDHEaD
Scooby Regular
 
SiDHEaD's Avatar
 
Join Date: Apr 2002
Location: Birmingham
Posts: 9,196
Likes: 0
Received 0 Likes on 0 Posts
Post

We've had it attempt to come into our work premises. Luckily all our email is screened at the ISP, and they use 3 virus scanners + they're own heuristic one. Bit worrying tho if that had got to one of the "less pc literate" users and managed to disable the desktop AV.

Andy
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Big RS Dave
ScoobyNet General
5
14 April 2001 08:12 PM



Quick Reply: How do you know if you've got BugBear virus?



All times are GMT +1. The time now is 06:58 PM.