Subject: MEDIA RELEASE: Bugbear e-mail worm spreading at an alarming rate
Date: Oct 2 22:41:19 2002
From: T Gronseth - tgronseth at yahoo.com


This press release comes from F-Secure. For more
information on F-Secure's mailing list policy,
see end of message.

PRESS RELEASE

For release Oct. 2, 2002

Bugbear e-mail worm spreading at an alarming rate

F-Secure raising alert to highest level as Bugbear
becoming the most
widespread virus currently in circulation

Helsinki, Finland, October 2, 2002 - The Bugbear
e-mail worm (also known as
Tanatos) was first seen on Monday, September 30. Since
then it has been
located in dozens of countries worldwide and continues
to spread at an
increasing rate. Current statistics show that
Bugbear/Tanatos has passed Klez
as the most common virus currently in the world. Klez
was the most common
virus for almost all of 2002.

Bugbear is a Windows mass mailer, spreading itself in
infected e-mail
attachments, sometimes executing the attachment
automatically. It also tries
to spread through open Windows fileshares. A side
effect of this is that the
worm sometimes prints massive amounts of nonsense text
on network printers.

The worm also attempts to terminate the processes of
various antivirus and
firewall programs. Once a machine is infected, it can
be remotely controlled
via a graphical backdoor, allowing the hacker to steal
and delete information
from affected computers.

VIRUS OPERATION

The worm can pick up old e-mail messages from an
infected system and send
them to random e-mail addresses. This means that
private e-mails will be
disclosed to third parties. "Forwarding old e-mails is
actually a social
engineering trick," comments Mikko Hypponen, Manager
of Anti-Virus Research
at F-Secure. "When people receive such e-mails, they
will be baffled by the
contents. In many cases they will click on the file
attachment just to figure
out what the strange e-mail is all about - thereby
becoming infected."

Some e-mails sent by Bugbear will use the IFRAME
vulnerability. This means
that on an unpatched Windows system the worm
attachment will execute
automatically as soon as it is previewed or read. In
some cases the worm
fakes the e-mail address of the sender - making it
look as if an innocent
third party sent the worm. This creates further
confusion and makes it
difficult to warn the infected parties of the problem.

The worm spreads effectively within corporate LANs
once one machine gets
infected via e-mail. The worm will enumerate all
network shares and try to
copy itself to them. On Windows machines with hard
drives shared for several
users, the worm attempts to copy itself to the Startup
folder, activating
when the machine is rebooted. The worm tries to copy
itself to all types of
shared network resources - including printers.
Printers will not and cannot
get infected by Bugbear, but they will attempt to
print out the binary code
of the worm - resulting in dozens or hundreds of pages
of garbage.

The Bugbear worm tries to terminate various processes
in the memory of an
infected computer. This includes processes used by
most of the popular
antivirus and personal firewall products - including
the outdated F-Secure
Anti-Virus v4.x series. However, the worm does not
affect the current
F-Secure Anti-Virus v5.x series. In any case, the worm
can only attack
security programs if it executes in the first place -
and up-to-date
anti-virus programs will prevent it from executing.
"As this worm is already
widespread, there must now be thousands and thousands
of computers in the
Internet without any antivirus or firewall protection,
because Bugbear has
removed them," comments Hypponen.

The worm will install a backdoor to all infected
systems. This backdoor can
be exploited by the virus writer or by hackers,
allowing them to connect to
infected machines using a web browser. The worm will
show a web user
interface through which the attacker can browse local
files or execute
programs. "We haven't seen such an advanced backdoor
in a worm before," says
Mikko Hypponen. "Fortunately, it is not easy for
script kiddies to enable
this functionality."

"It was such a nice and quiet year virus-wise - up
until the middle of
September," continues Hypponen. "After that we have
had many large outbreaks,
including the Slapper and Devnull Linux worms, and the
Opaserv and Bugbear
Windows worms."

The year 2001 is generally considered to have been the
worst virus year ever.
"During 2002, the Klez virus has been the most common
virus for months and
months. As Bugbear is quite similar to Klez in many
ways, I am afraid Bugbear
will still be widespread in 2003," finishes Mikko
Hypponen from F-Secure
Corporation.

A detailed technical description of the worm as well
as screenshots are
available in the Global Bugbear Information Center at
http://www.F-Secure.com/bugbear/ .

F-Secure Anti-Virus 5.40 can detect, stop and
disinfect the Bugbear worm,
even if the system is already infected with the worm.
F-Secure Anti-Virus can
be downloaded from
http://www.f-secure.com

About F-Secure Corporation

F-Secure Corporation is a leading provider of
centrally managed security for
today's mobile, wireless enterprise. The company
offers a full range of
award-winning, integrated anti-virus, file encryption,
distributed firewall
and VPN solutions for workstations, servers, gateways
and mobile devices.
F-Secure products are uniquely suited for delivery of
Security as a
Service(tm) which provides invisible, reliable,
always-on, and up-to-date
security for the most widely distributed user base.
Whether provided by
corporate IT or delivered by service providers,
F-Secure solutions extend
policy-based security and instant alerts to all
devices where information is
created, stored or accessed. Founded in 1988, F-Secure
Corporation is listed
on the Helsinki Exchanges [HEX: FSC]. The company is
headquartered in
Helsinki, Finland with North American head office in
San Jose, California, as
well as offices worldwide.

For more information, please contact:

Mikko Hypponen, Manager, Anti-Virus Research
F-Secure Corporation
Tel. +358 9 2520 5513
Email: Mikko.Hypponen at F-Secure.com

Tony Magallanez, Systems Engineer
F-Secure Inc.
Tel +1 (408) 350-2321
E-mail Tony.Magallanez at F-Secure.com

http://www.F-Secure.com


Mailing list policy

You have previously expressed interest in our
products, or have asked
to be included on one of our press release lists by
personally giving us
your e-mail address for this purpose. Our mailing list
are for the
exclusive use and the expressed purpose of F-Secure
and are not
sold or given to third parties.

If you no longer wish to receive our press releases,
or your email address
has been added to our lists without your consent, you
can unsubscribe at
http://www.F-Secure.com/news/subscribe.html

If you only wish to receive our press releases
concerning viruses,
please go to
http://www.F-Secure.com/news/subscribe.html
and first unsubscribe from
press-english-interest at lists.F-Secure.com
and then subscribe to
press-english-virus-announcement at lists.F-Secure.com


-------------------------------
Marita Nasman-Repo tel: +358 9 2520 5613
Deputy Communicator fax : +358 9 2520 5018
mobile: +358 40 517 4613

F-Secure Corporation
http://www.F-Secure.com

F-Secure: Securing the Mobile Enterprise

__________________________________________________
Do you Yahoo!?
New DSL Internet Access from SBC & Yahoo!
http://sbc.yahoo.com