Advertisement
Promo

Online business Toolkit

Fizzer virus secrets revealed

Published: 20 May 2003 11:31 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Members of the chat-network security group IRC/Unity have decoded the manner in which the creator of the Fizzer virus can communicate with the program, a co-founder of the group said on Monday.

The Fizzer virus connects from an infected PC to a randomly selected Internet relay chat (IRC) network using a list of more than 300 such networks contained in the virus. Once connected, Fizzer creates a chat channel and listens for commands from a specific user nickname. The IRC/Unity group discovered the algorithm that determines what that name should be.

"It's a three-letter nickname that is only valid for the current date," said John McGarrigle, the newly elected chairman of the IRC/Unity group, a collection of administrators from more than 50 different chat networks. "Once you have that, you can control the bot (virus program) through IRC."

The discovery occurred less than a week after smaller IRC networks became inundated with connection requests from compromised PCs. Late last week, the IRC/Unity group -- formed in response to the Fizzer worm -- started work on decompiling the program in an attempt to block the worm.

This weekend, the IRC/Unity group discovered that access to computers infected by the Fizzer worm is regulated by a three-letter nickname, which is generated by an algorithm that depends on the current date. A person who knows the nickname can issue commands to any computer that's compromised by the virus and listening to the current chat channel.

Several IRC operators have started using the information to command any PC infected with the virus that connects to their network to uninstall itself.

"A lot of networks are actively sending out the command to all IRC Fizzer clients," said McGarrigle. "When they send the uninstall command, it leaves no trace of the bot."

While the legality of the tactic is questionable, the actions could eradicate the virus from PCs in the coming weeks.

Still, the IRC/Unity group is not done yet. While it has determined the latest authorised nicknames for the virus, it hasn't learned all the specifics of the algorithm, which could hinder efforts to automate any response to the virus.

"There is still a lot of work," McGarrigle said. "Just because we have figured this out doesn't mean that we are going to (eliminate) the threat."


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
50 out of 108 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:











Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters