Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

How do you know if you've got BugBear virus?

Thread Tools
 
Search this Thread
 
Old Oct 11, 2002 | 04:48 PM
  #1  
ScoobyDoo555's Avatar
ScoobyDoo555
Thread Starter
Scooby Regular
 
Joined: Oct 2000
Posts: 11,217
Likes: 0
From: Does it matter?
Question

Don't think I've got it, but just being a bit wary...

What are the symtpoms etc?

Is it wirth running the bugbear antidote (from Norton) just in case, or will it screw up my PC?

TIV

Dan
Reply
Old Oct 11, 2002 | 04:55 PM
  #2  
Fuzz's Avatar
Fuzz
Scooby Regular
 
Joined: Jul 2002
Posts: 9,173
Likes: 0
From: Under your bonnet
Post

one would assume searching for the file "fwi acc details.t.exe" would do the trick.

Andy
Reply
Old Oct 11, 2002 | 04:57 PM
  #3  
MarkO's Avatar
MarkO
Scooby Regular
 
Joined: Oct 1998
Posts: 4,891
Likes: 0
From: London
Cool

Take a look at http://vil.nai.com/vil/content/v_99728.htm. It's got a link to a remover, too.
Reply
Old Oct 11, 2002 | 05:03 PM
  #4  
suba's Avatar
suba
Scooby Regular
 
Joined: Mar 2000
Posts: 2,462
Likes: 0
Post

link is here
Reply
Old Oct 11, 2002 | 05:04 PM
  #5  
DavidLewis's Avatar
DavidLewis
Scooby Regular
 
Joined: Apr 1998
Posts: 1,864
Likes: 0
Post

Fuzz, I'm not sure but the attached file in the affected eMail can be called almost anything. One of mine was called OldExcelDocuments.lnk.pif for instance
Reply
Old Oct 11, 2002 | 05:14 PM
  #6  
DavidLewis's Avatar
DavidLewis
Scooby Regular
 
Joined: Apr 1998
Posts: 1,864
Likes: 0
Post

For those that haven't checked it out yet....

The symptoms are

Port 36794 TCP open
Existence of the following files (* represents any character):
%WinDir%\System\****.EXE (50,688 or 50,684 bytes)
%WinDir%\******.DAT
%WinDir%\******.DAT
%WinDir%\System\******.DLL
%WinDir%\System\*******.DLL
%WinDir%\System\*******.DLL
Large Print jobs sent to network printers. The full printout caused by a copy of the worm in the printer queue can take about 500 pages. They are mostly blank with only one-two lines of random symbols on each page. The very first page starts with "MZ" followed by about 18 funny symbols and a string "=!This program cannot be run in DOS mode". Another visible printed string close to the beginning is "Rich5".

Reply
Old Oct 11, 2002 | 06:37 PM
  #7  
Fuzz's Avatar
Fuzz
Scooby Regular
 
Joined: Jul 2002
Posts: 9,173
Likes: 0
From: Under your bonnet
Post

I stand corrected, thanks dave
Don't know much about these things.. only got mine today..virus that is..not the pc

Andy
Reply
Old Oct 11, 2002 | 07:41 PM
  #8  
AndiThompson's Avatar
AndiThompson
Scooby Regular
 
Joined: Aug 2001
Posts: 2,474
Likes: 0
From: Republic Of Mancunia
Post

I've had it. E-Mail wasnt working on of the PCs at work, went to see, and was totally baffled. Whilst checking the normal stuff, noticed Norton wasnt running. So I started it, and a few seconds later, it closed itself, repeat 2 or 3 times before I got suspicious and checked the symantec site.

Recieved it in e-mail 5 times now, and all 5 were from computery related websites, most from aspsql.com and one from someone claiming to be something to do with internic.
Reply
Old Oct 12, 2002 | 10:14 PM
  #9  
SiDHEaD's Avatar
SiDHEaD
Scooby Regular
 
Joined: Apr 2002
Posts: 9,196
Likes: 0
From: Birmingham
Post

We've had it attempt to come into our work premises. Luckily all our email is screened at the ISP, and they use 3 virus scanners + they're own heuristic one. Bit worrying tho if that had got to one of the "less pc literate" users and managed to disable the desktop AV.

Andy
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Big RS Dave
ScoobyNet General
5
Apr 14, 2001 08:12 PM




All times are GMT +1. The time now is 11:22 PM.