Virus Win32/Fizzer.A, dalÜφ epidemie !

Virus Win32/Fizzer.A se zaΦal Üφ°it ohromnou rychlostφ, o Φem₧ sv∞dΦφ i report na strßnkßch MessageLabs.

Pochopiteln∞ se Üφ°φ elektronickou poÜtou a prost°ednictvφm KaZaA sφt∞ pro sdφlenφ dat mezi u₧ivateli. Krom∞ toho obsahuje backdoor (umo₧≥uje vzdßlenΘ ovlßdßnφ poΦφtaΦe ·toΦnφkem), kter² p°ijφmß rozkazy skrze mIRC.

P°edm∞t infikovanΘho emailu m∙₧e obsahovat jeden z t∞chto °etezc∙:

  • I thought this was interesting...
  • rather psychedelic...
  • found this on the net, you might like it...
  • discothèque
  • imbrue
  • Damn it feels good to be gangsta.
  • The way I feel - Remy Shand
  • Paradigm Shift
  • WASSUP!
  • Know Thyself
  • Hell
  • I love you
  • Please discard if you don't like or agree with our present leadership...
  • little popup remover
  • B cannot remember
  • Yo, WASSUP, B?
  • an interesting program...
  • You might not appreciate this...
  • I think you might find this amusing...
  • LOL
  • check this out... hehehe
  • question...
  • see you tomorrow.
  • how are you?
  • you need to lose weight.
  • why?
  • kind of simple, but fun nonetheless.
  • check it out.

    Do adresß°e Windows vypouÜtφ tento virus °adu soubor∙:
    iservc.exe, initbak.dat
    ProgOp.exe, iservc.dll, data1-2.cab, iservc.dat, Uninstall.pky, upd.bin

    Prvn∞ jmenovan² pak spouÜtφ automaticky p°i ka₧dΘm startu Windows, dφky zavedenφ do klφΦe v registrech:
    HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run

    DalÜφ modifikace provßdφ v klφΦi HKEY_LOCAL_MACHINE \ Software \ CLASSES \ txtfile \ shell \ open \ command (sprßvn∞ tam mß b²t notepad.exe %1).

    Backdoor, umo₧≥ujφcφ p°evzetφ kontroly nad poΦφtaΦem vzdßlenΘmu ·toΦnφkovi, vyu₧φvß porty 2018, 2019, 2020, 2021.

    A na zßv∞r pochopiteln∞ jedno·Φelov² antivirus :-) P°ed jeho pou₧itφm je doporuΦeno vypnout funkci RESTORE - OBNOVA SYST╔MU pod Windows ME / XP ! Viz. Jak se zbavit hav∞ti.