Skip Over Navigation Links
Center for Information TechnologyAntivirus
Antivirus Home Page
Contact Us
Questions or Comments
Disclaimers

Software
Current client downloads:
 VScan Engine/Dat (SuperDat) -5.2.00/4.0.5378
 VirusScan Enterprise 8.5i (with Patch 6) - Windows NT/2000/XP/2003
 VirusScan Enterprise 7.1 - Windows NT/2000/XP/2003
 Virex (OS X) Engine/Def - 7.2(v1.1)/080903
 Virex (OS 9.x) Engine/Def - 6.2/071001
 Linux & Solaris Engine/Dat - 5.2.00/4.0.5196
 Symantec Antivirus - 10.1.7.7000
 Symantec Antivirus - 10.2
 Clean Boot 1.0
 Stinger v3.8.0 virus removal tool (Updated 09/10/07)
Current server downloads:
 VirusScan Enterprise 8.5
 VirusScan Enterprise 7.1
 NetShield NetWare - 4.6.2
 NetShield NetWare - 4.6.3
 NetShield NetWare Engine Update - 4.4.00
 ePO agent for NetWare
 ScanMail eManager - 3.0

Information
 ePO 3.0/VirusScan 7.0 Presentation
 Virex 7.x Installation Instructions
 VirusScan FAQs
 VirusScan Instructions
 Additional Resources

Archives
 List of Viruses

Virus Archives

w32/BugBear.B Last Updated 06/05/03 1:50pm

w32/BugBear.B is an email virus that infects Windows machines and is spreading in the wild. w32/BugBear.B is a mass mailing worm that also spreads through open network shares and installs a keylogger Trojan. The worm spoofs the address of the sender with a random address and uses its own SMTP engine to send mail from the infected client.

The subject of the email is taken from an existing email in the infected clients inbox.

The attachment name is a filename taken from files found on the infected machine and is known to have either a .PIF, .EXE, or .SCR extension.

The body of the message varies and may include file fragments.

When w32/BugBear.B runs it will attempt to copy itself to the startup folder using a random file name. After copying itself to the startup folder of the local machine it will attempt to copy itself to the startup folder of other machines on the network.

w32/BugBear.B also installs a keylogger Trojan. The file name of the keylogger is a randomly generated with a .dll extension and is placed in the SYSTEM directory. The information collected by the Keylogger is placed in 2 similarly named files also in the SYSTEM directory. The Trojan listens on port 1080.

w32/BugBear.B will also try to infect files try to terminate antivirus and firewall software running on the infected machine.

The current 4270 Dat/SuperDat released by NAI will detect and remove w32/BugBear.B.

Symantec definitions dated 6-5-2003 and later detect and remove w32/BugBear.B. The definitions are available through the LiveUpdate feature of Norton Antivirus.

For more information see:

http://vil.nai.com/vil/content/v_100358.htm from NAI regarding w32/BugBear.B.

http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbear.b@mm.html from Symantec regarding w32/BugBear.B.

This archive is not intended to be comprehensive. For a more complete virus library, please visit NAI's Virus Information Library at http://vil.nai.com.

Contact NIH Help Desk for assistance:
866-319-4357 (toll free), 301-496-4357 (6-HELP) (local), 301-496-8294 (TDD)
http://ithelpdesk.nih.gov/support
Register for iForgotMyPassWord

National Institutes of HealthCenter for Information Technology
National Institutes of Health
Bethesda, Maryland 20892

Questions or Comments | Disclaimers | Privacy Policy

Department of Health and Human ServicesHealth and Human Services
Washington, D.C. 20201
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -