Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Fizzer worm spreading

Could allow attackers access to infected systems


May 12, 2003
 

A new computer worm spreading over the Internet captures a user's keystrokes and creates a back door that could give an attacker access to the infected system or enable the machine to secretly be used in a denial of service attack.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

The new worm, named "Fizzer," first appeared on May 8 and propagates using a wide range of methods, according to alerts posted by leading antivirus companies.

First and foremost, Fizzer is a mass-mailing worm, hiding in executable attachments to e-mail messages with seductive subject lines, said Vincent Gullotto, vice president of Avert Labs at Network Associates. The virus is contained in executable e-mail attachments with names such as "Jesus123.exe" that are generated randomly from lists maintained by the worm.

Messages containing the virus arrive in victims' e-mail inboxes with subjects such as "You might not appreciate this...," "Re: how are you?" and "I thought this was interesting..." according to alerts posted by antivirus companies McAfee, which is part of Network Associates, and F-Secure.

Fizzer affects machines running versions of Microsoft]'s Windows operating system and is capable of spreading through vulnerable shared directories on computer networks and over the Kazaa peer-to-peer network, McAfee said.

"It's a complex little beast," Gullotto said. "The virus has a complex set of routines it's going through and it covers a majority of the ways it could infect [a system]."

McAfee first received copies of the new worm from enterprise and consumer customers on Thursday. While the initial number of reports was low, the pace of infection appears to have increased in the last 24 hours. During that time, McAfee received reports of Fizzer from five or six different countries, Gullotto said.

That activity prompted McAfee to raise its risk profile for Fizzer early Monday from "low" to "medium-on-watch."

Gullotto likened Fizzer to September's W32/BugBear mass-mailing worm, which began spreading slowly only to pick up steam and become a high-priority event.

The new worm does not exploit any specific product vulnerability, Gullotto said. Instead, Fizzer takes advantage of commonly used channels of online communication to spread itself.

"[Fizzer] is taking good technology that's been created for communication purposes and using it to spread on people's machines," he said.

The decision to use multiple means to spread may be a reaction to the increased effectiveness of gateway and desktop antivirus systems at detecting and stopping mass-mailing worms, Gullotto said.

"Virus writers are not succeeding in getting mass mailers to work, so this is a carpet bombing or proof-of-concept approach -- to try many different routes," he said.

Besides using multiple means to propagate, Fizzer exploits common Internet applications such as AOL Instant Messenger and Internet Relay Chat (IRC) clients to connect to Internet servers and listen for further instructions from an attacker, McAfee said.

Fizzer's key logging functionality enables it to capture typed keystrokes on the machines it infects and store them in an encrypted file. An attacker could subsequently retrieve those files and mine them for passwords and other sensitive personal data, McAfee said.

McAfee was unable to pinpoint a source of the virus, but the worm does contain a message, presumably from the virus' author, that points the finger back at the antivirus companies, F-Secure said.

"I sent this program...from anonymous places on the net...Did you ever stop to think that viruses are good for the economy? Maybe the primary creators of the world's worst viruses are the companies that make the Anti-Virus software," the message read, in part.

To protect themselves from Fizzer, users should update their antivirus software's virus definitions as soon as possible, Gullotto said.

Because e-mail is not the only means by which the virus spreads, users with the Kazaa client installed should understand that they are at increased risk and deploy a firewall if one is not already installed, he said.

Users who have already been infected can remove the worm by deleting the worm file, "Iservc.exe," from the Windows directory, F-Secure said.





 

TOP NEWS:


»  Antitrust review of Google-Yahoo deal no surprise
While serious antitrust problems are unlikely, both Google and Yahoo expected their partnership to be subjected to instense DOJ scrutiny

»  Top 10: Coreflood, more Microsoft-Yahoo, iPhone plans
This week's wrapup of the top tech news stories includes more Microsoft-Yahoo rumors, iPhone updates, Flash searches, Oracle's BEA roadmap, and more

»  Four 'important' Microsoft patches due Tuesday
Not rated "critical," fixes apply to "Elevation of Privileges" and "spoofing" bugs for Windows, Exchange, and SQL

»  Judge grants RIM a stay in Visto patent trial
Trial delayed from beginning next week while patent office studies validity of certain parts of e-mail provider Visto's patents as requested by RIM

»  Developers satisfied with Apple's enterprise work
Mac developers feel that Apple shouldn't try to make a broad attempt to win over enterprises and should instead focus on certain areas within the enterprise

»  Opera patches multiple bugs in flagship browser
Opera 9.5.1 fixes several flaws, including one ranked 'highly critical'




Solutions to the Toughest IT Challenges in Remote Offices
Though small in size, remote offices face many of the same IT challenges as larger central offices. This Webcast zeroes in on the top line challenges to deliver information that can provide immediate benefits to your business. Sponsor: AMD and Dell

»  Click here to view this Webcast
  The Silver Lining: Cloud Computing
This IT Strategy Guide digs deep into cloud computing helping put you ahead of the curve on this hot topic. It explores the differences between cloud computing, grid computing and utility computing and then helps you see where and how each applies to your business. Sponsored by Box.net

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist