Home Clinic Anti-Virus Download PC Checkup Shopping Y2K Support
McAfee.com logo
  Search  
    
  
My Account Info  
Click here to download software manuals
Virus Or Hoax? McAfee.com's Virus Information Center includes a list of virus hoaxes. Find out whether that warning you received is legit!
VBS/Bubbleboy Help Center
VBS/Bubbleboy is a new Internet worm, discovered 11/08/99. AVERT has assigned it a LOW risk assessment; it has not appeared in the wild.

VBS/Bubbleboy is a NEW type of worm: Unlike previous worms transmitted through email, this new type of worm does not come as an executable attachment. Instead, VBS/Bubbleboy infects PCs as soon as the transmitting email message is opened. This is a VERY significant innovation! In the past, it was not possible to contract a virus or worm merely by opening and reading an email message. This is no longer true, and VBS/Bubbleboy marks the beginning of a more dangerous computing environment.

VBS/Bubbleboy is transmitted through an email message with the subject heading "Bubbleboy is back!" It will ONLY infect PCs running Windows 98 with Internet Explorer 5 and Outlook or Outlook Express. PCs using Outlook are infected upon opening the email message, while Outlook Express users may be infected by viewing the message with Outlook Express's "Preview Pane" feature! When the email is opened, the worm creates a file called UPDATE.HTA. The next time the PC is booted up, the worm sends itself embedded in an email to EVERY address in EVERY MS Outlook address book on the local system. It does this only once.

Notes on detection, removal, and protection:
VirusScan Online (Scan Now and ActiveShield) has been updated to detect VBS/Bubbleboy.
VirusScan 4.0.25 and above require the EXTRA.DAT (bubb-4.exe) in order to detect VBS/Bubbleboy.
Microsoft has issued a patch for Internet Explorer 5 that will prevent the worm from executing under default security settings.
If the worm is detected before it has sent itself to your address book contacts, you should find and delete the file UPDATE.HTA. If the worm has already sent itself to your contacts, you should do nothing; the worm will not do anything further, and your PC is now effectively inoculated against re-infection. To protect your system against infection, disable Windows Scripting Host by following these steps: Click the Start button, Settings, Control Panel, then select Add/Remove Programs, then select the Windows Setup tab, then double-click Accessories, scroll down to Windows Scripting Host, and uncheck the box. Save changes and close the window.

 

What people are saying about McAfee.com

"You folks do a nice job of getting a bunch of options in view and still feeling uncluttered -- I spend my life on the Web as a sales consultant, and your site was the easiest to use in recent memory."

—Joe Viz

FREE Online File Storage |  Best Peripheral Prices |  Virtual Bookstore |  FREE Email And More |  Personal Browser
McAfee.com logo   Products |  Feedback |  About Us |  Advertising |  Press/News |  Jobs |  Affiliates |  Partners |  Site Index
Copyright 1999 McAfee.com Corporation / All Rights Reserved   Please read our Privacy Policy.