|
The worm uses the Incorrect MIME Header Can Cause IE to Execute E-mail Attachment vulnerability to cause unpatched systems to auto-execute the worm when reading or previewing an infected message.
In addition, the worm contains routines that specifically affect financial institutions. This functionality will cause the worm to send sensitive data to one of ten hard-coded public Internet e-mail addresses. The information sent includes cached passwords and key-logging data.
Because the worm does not properly handle the network resource types, it may flood shared printer resources, which causes them to print garbage or disrupt their normal functionality.
The download Removal Tool does the following:
- It terminates the viral W32.Bugbear.B@mm processes.
- It deletes the non-repairable W32.Bugbear.B@mm files and the Trojan that the worm drops (detected by Symantec antivirus products as PWS.Hooker.Trojan)
- It repairs the W32.Bugbear.B@mm infected files.
|