ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Fizzer virus secrets revealed

Published: 20 May 2003 11:31 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Members of the chat-network security group IRC/Unity have decoded the manner in which the creator of the Fizzer virus can communicate with the program, a co-founder of the group said on Monday.

The Fizzer virus connects from an infected PC to a randomly selected Internet relay chat (IRC) network using a list of more than 300 such networks contained in the virus. Once connected, Fizzer creates a chat channel and listens for commands from a specific user nickname. The IRC/Unity group discovered the algorithm that determines what that name should be.

"It's a three-letter nickname that is only valid for the current date," said John McGarrigle, the newly elected chairman of the IRC/Unity group, a collection of administrators from more than 50 different chat networks. "Once you have that, you can control the bot (virus program) through IRC."

The discovery occurred less than a week after smaller IRC networks became inundated with connection requests from compromised PCs. Late last week, the IRC/Unity group -- formed in response to the Fizzer worm -- started work on decompiling the program in an attempt to block the worm.

This weekend, the IRC/Unity group discovered that access to computers infected by the Fizzer worm is regulated by a three-letter nickname, which is generated by an algorithm that depends on the current date. A person who knows the nickname can issue commands to any computer that's compromised by the virus and listening to the current chat channel.

Several IRC operators have started using the information to command any PC infected with the virus that connects to their network to uninstall itself.

"A lot of networks are actively sending out the command to all IRC Fizzer clients," said McGarrigle. "When they send the uninstall command, it leaves no trace of the bot."

While the legality of the tactic is questionable, the actions could eradicate the virus from PCs in the coming weeks.

Still, the IRC/Unity group is not done yet. While it has determined the latest authorised nicknames for the virus, it hasn't learned all the specifics of the algorithm, which could hinder efforts to automate any response to the virus.

"There is still a lot of work," McGarrigle said. "Just because we have figured this out doesn't mean that we are going to (eliminate) the threat."


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
49 out of 106 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Windows Engineer

In the battle-space arena CSIS provide Command and Control systems for all three services, including the IT Infrastructure that these systems operate ...

Firewalls Engineer Lead

Good working knowledge of anti virus technologies. Desirable - Fully Securtiy cleared - if you do not posess SC clearance then this can be resolved ...

HEO Intranet Support & Development Officer

To apply, please submit a CV and covering letter stating why you feel you are the right person for the job. A customer-focused attitude certainly ...

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains