Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Fizzer worm spreading

Could allow attackers access to infected systems


May 12, 2003
 

A new computer worm spreading over the Internet captures a user's keystrokes and creates a back door that could give an attacker access to the infected system or enable the machine to secretly be used in a denial of service attack.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

The new worm, named "Fizzer," first appeared on May 8 and propagates using a wide range of methods, according to alerts posted by leading antivirus companies.

First and foremost, Fizzer is a mass-mailing worm, hiding in executable attachments to e-mail messages with seductive subject lines, said Vincent Gullotto, vice president of Avert Labs at Network Associates. The virus is contained in executable e-mail attachments with names such as "Jesus123.exe" that are generated randomly from lists maintained by the worm.

Messages containing the virus arrive in victims' e-mail inboxes with subjects such as "You might not appreciate this...," "Re: how are you?" and "I thought this was interesting..." according to alerts posted by antivirus companies McAfee, which is part of Network Associates, and F-Secure.

Fizzer affects machines running versions of Microsoft]'s Windows operating system and is capable of spreading through vulnerable shared directories on computer networks and over the Kazaa peer-to-peer network, McAfee said.

"It's a complex little beast," Gullotto said. "The virus has a complex set of routines it's going through and it covers a majority of the ways it could infect [a system]."

McAfee first received copies of the new worm from enterprise and consumer customers on Thursday. While the initial number of reports was low, the pace of infection appears to have increased in the last 24 hours. During that time, McAfee received reports of Fizzer from five or six different countries, Gullotto said.

That activity prompted McAfee to raise its risk profile for Fizzer early Monday from "low" to "medium-on-watch."

Gullotto likened Fizzer to September's W32/BugBear mass-mailing worm, which began spreading slowly only to pick up steam and become a high-priority event.

The new worm does not exploit any specific product vulnerability, Gullotto said. Instead, Fizzer takes advantage of commonly used channels of online communication to spread itself.

"[Fizzer] is taking good technology that's been created for communication purposes and using it to spread on people's machines," he said.

The decision to use multiple means to spread may be a reaction to the increased effectiveness of gateway and desktop antivirus systems at detecting and stopping mass-mailing worms, Gullotto said.

"Virus writers are not succeeding in getting mass mailers to work, so this is a carpet bombing or proof-of-concept approach -- to try many different routes," he said.

Besides using multiple means to propagate, Fizzer exploits common Internet applications such as AOL Instant Messenger and Internet Relay Chat (IRC) clients to connect to Internet servers and listen for further instructions from an attacker, McAfee said.

Fizzer's key logging functionality enables it to capture typed keystrokes on the machines it infects and store them in an encrypted file. An attacker could subsequently retrieve those files and mine them for passwords and other sensitive personal data, McAfee said.

McAfee was unable to pinpoint a source of the virus, but the worm does contain a message, presumably from the virus' author, that points the finger back at the antivirus companies, F-Secure said.

"I sent this program...from anonymous places on the net...Did you ever stop to think that viruses are good for the economy? Maybe the primary creators of the world's worst viruses are the companies that make the Anti-Virus software," the message read, in part.

To protect themselves from Fizzer, users should update their antivirus software's virus definitions as soon as possible, Gullotto said.

Because e-mail is not the only means by which the virus spreads, users with the Kazaa client installed should understand that they are at increased risk and deploy a firewall if one is not already installed, he said.

Users who have already been infected can remove the worm by deleting the worm file, "Iservc.exe," from the Windows directory, F-Secure said.





 

TOP NEWS:


»  Four quick tips for choosing an IM security product
71 percent of businesses will invest in real-time messaging this year. If you're one of them, be sure to protect your enterprise

»  Forrester analysts ID hot IT jobs
Research group finds 16 IT roles with a promising future

»  Nvidia claims 10 hours of HD video on Tegra chip
The Tegra 600 and 650 can be used with hard disk drives and are designed partly for mobile Internet devices

»  Database vendors add Google's MapReduce
Greenplum and Aster Data Systems will support Google's programming technique, developed for parallel processing of large data sets across commodity hardware

»  Network management: Tips for managing costs
New technologies, changing requirements, and ongoing equipment maintenance and upgrades cost money, but there are ways to manage expenses

»  EMC targets SMBs, branch offices with new low-end storage
Celerra NX4 highlights include thin provisioning, snapshot technology for data recovery and backups, and Web-based console for management of storage volumes




Take control of your content- leverage Microsoft SharePoint
Microsoft Office SharePoint Server (MOSS) offers core content management designed for a broad user population. Attend this webcast to learn how to implement a strategy that allows for the coexistence of both MOSS and advanced ECM solution within the same IT environment. Sponsor: IBM

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist