PDA

View Full Version : Dear Rogers Customer...another one!


deb
06-09-2003, 06:41 AM
You may receive an Email message that contains an infected attachment.
The name of the virus is W32/Bugbear.b@MM. The virus disguises itself
as a number of different file attachment types. If the attachment is
opened, the virus can potentially:
* Make copies of itself and send itself (without your knowledge) to
everyone in your Email program's address book.
* Attempt to alter a number of program files on your computer.
* Attempt to shut down and corrupt many of the most popular virus
protection and firewall software packages.
* Open a back door on your computer which can potentially allow malicious
individuals to log your keystrokes as well as attack other computers
and networks from your computer. (Trojan Capabilities)

If you do not have the latest security patches for your version of
Internet Explorer and Outlook Express, the virus can auto-execute
(run the attachment without you double-clicking it).

A key indicator of the virus within an Email message is that the file
has a double extension (i.e. the last part of the file name, for
example: card.gif.pif). If the first or second extension is appears as:
.pif .scr .exe .bat

Do NOT open the message, delete it immediately and ake sure that you
empty your deleted items folder.
As a result of the potentially serious nature of this virus, we
strongly recommend that you do the following before accessing your
Email:
1. Visit the Microsoft Update Website to ensure that you have the
latest security patches for Internet Explorer and Outlook Express
- <http://windowsupdate.microsoft.com/>
2. Update your Anti-Virus Software to ensure that you have the latest
virus description & cleaning file components.

Following are details on the Email message containing the virus:

To:
- This message has been sent to numerous Email users all over the
Internet Date Sent: (Varies)

From: (Varies)
FROM NOTES:
- The W32/Bugbear.b@MM virus makes it appear that the infected Email is
coming from someone who has your email address in their contact list
or email address book.

Subject:
- May contain one of the following subject lines (but not limited to):

- 25 merchants and rising Announcement
- bad news
- CALL FOR INFORMATION!
- click on this!
- Correction of errors
- Cows
- Daily Email Reminder
- empty account
- fantastic
- free shipping!
- Get 8 FREE issues - no risk!
- Get a FREE gift!
- Greets!
- Hello!
- Hi!
- history screen
- hmm..
- I need help about script!!!
- Interesting...
- Introduction
- its easy
- Just a reminder
- Lost & Found
- Market Update Report
- Membership Confirmation
- My eBay ads
- New bonus in your cash account
- New Contests
- new reading
- News
- Payment notices
- Please Help...
- Re: $150 FREE Bonus!
- Report
- SCAM alert!!!
- Sponsors needed
- Stats
- Today Only
- Tools For Your Online Business
- update
- various
- Warning!
- wow!
- Your Gift
- Your News Alert

BODY OF THE EMAIL MESSAGE: (Varies)

Attachment Name:
The infected attachment filename may have one of the
following the extensions (the part of the filename after the '.'):

.reg .ini .bat .diz .txt .cpp .html .htm .jpeg .jpg .gif
.cpl .dll .vxd .sys .com .exe .bmp

- Additionally, the filename may have one of the following second
extensions (for example: card.gif.pif):

.scr .pif .exe

File Size of the Attachment: (varies)

Details: Providing that you have the latest security patches for
Internet Explorer and Outlook Express from the Windows Update service,
this virus will not infect your computer unless you have opened the
attachment.

Steps for cleaning the W32/Bugbear.b@MM

IF YOU HAVE OPENED THE INFECTED ATTACHMENT:

1. If you do not already own one, download an updated Anti-Virus
software package. These virus-scanning packages can be downloaded
from:

McAffee http://software.mcafee.com/centers/download/default.asp

Norton Antivirus http://www.symantec.com/downloads/

NOTE: Even if you own a virus scanning software package, it is very
important that you download the latest virus definition file so that
your software can clean this new virus.

1. Run your virus scanning software which will detect the
W32/Bugbear.b@MM Virus and offer to clean it from your system.
Select the option that cleans it from your system.

2. Read through the steps in the Surf Safe section on our customer
support site to keep your computer safe. The Surf Safe section
can be found at: http://rogers.home.com/help/content/how/surf_safe/

IF YOU HAVE RECEIVED THE EMAIL, BUT HAVE NOT OPENED THE INFECTED
ATTACHMENT:

1. Delete the Email Message.

2. Empty your deleted Email folder.

3. Update your existing Anti-Virus Software or purchase one of the
packages listed above.

4. Read through the steps in the Surf Safe section on our customer
support site to keep your computer safe. The Surf Safe section
can be found at: http://rogers.home.com/help/content/how/surf_safe/

Please note that although our Network Security team monitors viruses
on the Rogers network, we strongly recommend that you consistently scan
your Email attachments and downloaded files to protect your personal
computer, no matter how trusted the source. This advice applies to all
Email messages, not just the one discussed in this message.
Please rest assured that the Rogers Network Security Team will continue
to monitor the situation.

Thank you,
Rogers Network Security

-mander-
06-09-2003, 07:52 AM
There is also a tool that can be downloaded for removing it, just incase someone did get it. That can be found here:

http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbear.b@mm.removal.tool.html