Recently, Jiang min recently detected a network worm named W32/Fusic, which has the backdoor capability and can copy emails, it uses MAPI to send itself to contacts in the Windows Address Book. The virus size is 212992 bytes 24576 bytes 69632 bytes. the infected system is applicable to all WINDOWS systems except WINDOWS 3.x and windows iis.
Jiang min anti-virus expert: During the virus running, the hacker will be directed to the systemkernelkernel32.exe file, and two files will be created under the System Directory: FuncDLL. dll and IEHelper. dll. These two file Trojans use hooks to intercept keyboard messages. IEHelper. dll can intercept events when a user inputs content to a web field in the IE browser. The intercepted data and URL are recorded in the systemPasslogx. log file. If this file exists in the system, it indicates that the system may have been infected and can be used to know which information has been intercepted.
The worm adds the following key values to the Registry that contain configuration file information:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun,
Kernel systemkernelkernel32.exe
HKEY_LOCAL_MACHINESOFTWAREkernel
HKEY_LOCAL_MACHINESOFTWAREkernelA09b37xz
If the system is Windows 95/98/Me, it registers itself as a service process, so that the system is still running after cancellation, and stops running only after the system is shut down.
Virus install a hook process to monitor the keyboard and mouse messages in the system, start to wait for remote client commands, hackers obtain important information about the system and network through remote control.
When sending a virus email, the system checks the recipient's region. If the recipient is not from China, the email is sent in English. If the recipient is from China, the email is displayed in Chinese.
Jiang min reminded users: Please upgrade the KV3000 AntiVirus Virus database in time to KV3000 immediately before the virus is effective.
To manually clear an infected user, follow these steps:
1. Update the KV3000 antivirus database, scan the system comprehensively, and delete all files detected to be infected with W32/Fusic;
2. Open the registry and delete the following key values:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun,
Kernel systemkernelkernel32.exe
HKEY_LOCAL_MACHINESOFTWAREkernel
HKEY_LOCAL_MACHINESOFTWAREkernelA09b37xz