Prevent W32/Fusic email viruses from sending hooks to your computer

Source: Internet
Author: User

Recently, Jiang min recently detected a network worm named W32/Fusic, which has the backdoor capability and can copy emails, it uses MAPI to send itself to contacts in the Windows Address Book. The virus size is 212992 bytes 24576 bytes 69632 bytes. the infected system is applicable to all WINDOWS systems except WINDOWS 3.x and windows iis.

Jiang min anti-virus expert: During the virus running, the hacker will be directed to the systemkernelkernel32.exe file, and two files will be created under the System Directory: FuncDLL. dll and IEHelper. dll. These two file Trojans use hooks to intercept keyboard messages. IEHelper. dll can intercept events when a user inputs content to a web field in the IE browser. The intercepted data and URL are recorded in the systemPasslogx. log file. If this file exists in the system, it indicates that the system may have been infected and can be used to know which information has been intercepted.

The worm adds the following key values to the Registry that contain configuration file information:

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun,

Kernel systemkernelkernel32.exe

HKEY_LOCAL_MACHINESOFTWAREkernel

HKEY_LOCAL_MACHINESOFTWAREkernelA09b37xz

If the system is Windows 95/98/Me, it registers itself as a service process, so that the system is still running after cancellation, and stops running only after the system is shut down.

Virus install a hook process to monitor the keyboard and mouse messages in the system, start to wait for remote client commands, hackers obtain important information about the system and network through remote control.

When sending a virus email, the system checks the recipient's region. If the recipient is not from China, the email is sent in English. If the recipient is from China, the email is displayed in Chinese.

Jiang min reminded users: Please upgrade the KV3000 AntiVirus Virus database in time to KV3000 immediately before the virus is effective.

To manually clear an infected user, follow these steps:

1. Update the KV3000 antivirus database, scan the system comprehensively, and delete all files detected to be infected with W32/Fusic;

2. Open the registry and delete the following key values:

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun,

Kernel systemkernelkernel32.exe

HKEY_LOCAL_MACHINESOFTWAREkernel

HKEY_LOCAL_MACHINESOFTWAREkernelA09b37xz

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.