Spyware Doctor
PestPatrol Anti-Spyware
WinTasks 5 Pro
McAfee VirusScan
WebMail Spy
Panda Antivirus + Firewall 2007
BPS Adware and Spyware Remover
X-Cleaner
iSpyNOW
Smart Protector Pro
Anti-Keylogger CE
BlazingTools Perfect Keylogger
SpeedUpMyPC

Anti-Keylogger
Anti-Spam
Anti-Virus
Online Privacy
PC Monitoring
Personal Firewall
Spyware Remover
System Tool

How to Detect and Remove  eUniverse  Hijacker
How to Detect and Remove  CoolWebSearch Hijacker
How to Detect and Remove  NetSky.P Worm Virus
How to Detect and Remove  MoneyTree Dialer
How to Detect and Remove  n-NASE Adware
How to Detect and Remove  Spector Keylogger
How to Detect and Remove  SDBot Backdoor
How to Detect and Remove  CnsMin Hijacker
How to Detect and Remove  Web_Rebates Adware
How to Detect and Remove  TV Media Display Adware

Sign up for free up-to-date messages about your PC's security & privacy
              Email
Confirm email
     Your Name
  
Home » Articles » Removal Instructions for Worms » BugBear
Removal Instructions for BugBear

About BugBear

Also known as: W32.Bugbear@mm, W32/Bugbear-A, W32/Bugbear.A@mm, W32/Bugbear.worm, W32/Tanat, W32/Tanat-mm, Win32Bugbear, Worm/Tanatos, WORM_NATOSTA.A

This worm has the ability to spoof, or forge, the 'From:' field. (Often set to an address found on the victim's machine). Additionally the virus can use a fabricated from address, by taking the name before the "@" sign of one address, and the domain name after the "@" sign of another address. (ie. name1@domain1.com + name2@domain2.com = name1@domain2.com)

This virus is written in MSVC and packed with UPX. It affects systems running the Windows operating system. It does not affect MacOS or Linux environments. It spreads via network shares and by emailing itself. It also contains a backdoor trojan component that contains keylogging functionality.

......

Variants:


Removal Instructions
Automatic Removal:

BugBear can be detected and removed AUTOMATICALLY by McAfee VirusScan.

Once infected, VirusScan may not be able to run as the virus can terminate the process before any scanning/removal is accomplished.

The following steps will circumvent the virus and allow for proper VirusScan scanning/removal, by using the command-line scanner.

  1. Ensure that you are using the minimum DAT (specified above) or higher
  2. Close all running applications
  3. Disconnect the system from the network
  4. Click START | RUN, type command and hit ENTER
  5. Change to the VirusScan engine directory:
    • Win9x/ME - Type cd \progra~1\common~1\networ~1\viruss~1\40~1.xx and hit ENTER
    • WinNT/2K/XP - Type cd \progra~1\common~1\networ~1\viruss~1\4.0.xx and hit ENTER
  6. Type scan.exe /adl /clean and hit ENTER
  7. After scanning and removal is complete, reboot the system and reconnect to the network

Additional Windows ME/XP removal considerations

Sponsored Links:

Removal Instructions for Other Worms

Remove Bagle Remove Welchia
Remove Doomjuice Remove Dumaru
Remove Galil Remove Lovsan
Remove Mydoom Remove NetSky
Remove Swen Remove Vesser
More ... 

Premium Software

iNet-Mate.com uses and recommends:

Free Registry Scan!
94% of PC's have corrupt, unused and possibly harmful files. Clean, repair, and optimize your system with the #1 industry leading and award-winning Registry Booster from Uniblue. Start Free Scan

Boost Your PC Now!
Most PCs are not Optimized for Peak Performance! SpeedUpMyPC - the award winning utility software that ensures your PC is automatically optimized for maximum performance in just a few easy clicks. Free Scan Now

Copyright ©2004-2007 iNet-Mate.com. All rights reserved. Other Trademarks are the sole property of their respective owners.