Latest Web Technology News and Web Technologies May 12 2003, the latest breaking New York Web design news brought to you by,
Web Designs Now,Website Designs Now,New York Web Design Homepage,Web Design Services for New York, Connecticut, Long Island,New York Web Design Client Testimonials,Website Portfolio of New York Web Design, About this New York Web Design Firm,Contact this New York Web Design Firm

Fizzer Worm Spreads Across the Internet
Latest Web Technology & Web Design News, May 12, 2003

Microsoft Pulls Windows XP Update
Google 5X Faster?
Kazaa's Serious Vulnerability
SPS Receives $18M
Web Services to Alter Consulting
W3C Makes Patent Ban Final
Web Services 'Yellow Pages'
MS Launches Antivirus Info Site
Surfers On High-Speed Waves

Yahoo! Searches Public Eye
Fizzer Worm Spreads
E-Business Bounces Back
Dot-Coms Regain Their Luster
E-commerce Grows Nicely
USA Interactive Soars
Google Tops Competition
Yahoo! Acquires Inktomi

More Web Design News:
2011 Latest Web Technology News
2011 April
2011 March
2010 December
2009 April
2008 November
2008 October
2008 July
2008 June
2007 June
2007 May
2007 March
2006 November
2006 September
2006 August
2006 July
2006 June
2006 May
2006 April
2006 March
2006 February
2006 January
2005 December
2005 November
2005 October
2005 September
2005 August
2005 July
2005 June
2005 May
2005 April
2005 March
2005 February
2004 March
2004 February
2004 January
2003 December
2003 November
2003 October
2003 September
2003 August
2003 July
2003 June
2003 March - May



May 12, 2003

A very clever mass-mailing worm is spreading rapidly across the Internet.
By Robert Vamosi

Fizzer (w32.fizzer@mm) has many different components, each timed to trigger different processes, making it quite difficult to contain.

The worm spreads via e-mail and includes its own SMTP engine to bypass any security your e-mail client may have. Fizzer also spreads via Kazaa, a popular file-sharing application.

The worm is self-updating, connecting to a GeoCities account for the latest update, and it also establishes its own accounts on Internet Relay Chat (IRC) and AOL Instant Messenger, in order to await further instructions from the virus author.

Fizzer attempts to disable any antivirus program running at the time of infection. Systems infected with Fizzer could be used in distributed denial-of-service (DDoS) attacks on other computers.

Fizzer includes a keystroke-logging Trojan horse, which can be used to steal passwords words and credit card information.

Because Fizzer spreads via e-mail and Kazaa, contains a keystroke-logging Trojan horse, and could be used in a DDoS attack, this worm rates a 7 on the ZDNet Virus Meter.

How it works
Fizzer arrives as e-mail with several possible subject lines and body texts. The From: address can be forged and therefore should not be trusted. Fizzer's attached files contain one of the following extensions: .com, .exe, .pif and .scr.

If a user opens the attached file or otherwise activates the worm, three files are added to the Windows directory:
initbak.dat, which is a copy of the worm
iservc.exe, which is a copy of the worm
progop.exe
iservc.dll
, which contains the keystroke logging Trojan

According to McAfee, Fizzer modifies the system Registry in the following ways:

Hkey_local_machine\Software\Microsoft\Windows\CurrentVersion\ Run "SystemInit" = C:\Windows\iservc.exe

Hkey_classes_root\txtfile\shell\open\command "(Default)" = C:\Windows\progop.exe 0 7 'C:\Windows\Notepad.exe %1' 'C:\Windows\initbak.dat' 'C:\Windows\iservc.exe'

Hkey_classes_root\Applications\progop.exe

On Windows NT, 2000, and XP systems, Fizzer also creates a service named S1Trace.

This worm listens for external Internet traffic in various ways.
Signs of infection include unexpected traffic on port 6667 (IRC) and 5190 (AIM).

Removal
Most antivirus software companies have updated their signature files to include this worm. This will stop the infection upon contact and in some cases will remove an active infection from your system. For more information, see Central Command, F-Secure, McAfee, MessageLabs, Sophos, Symantec, or Trend Micro.

Web Designs Now
Back to the Top


 © Copyright 2011, All rights reserved  |  Privacy Web Design Forums  |  Web Design News  |  Advertise  |  About Us  |  Contact Us  |  W3C HTML 
 Related Websites: New-York-WebDesign.com