Raghav SR Blog

Archives

Links

Meta







Fujacks Virus.

November 5th, 2007

Fujacks Virus

Virus spread when Anti-virus is in a pathetic state. My whole college is infected with Fujacks Virus and all the students accessing those files in their home via Usb are also affected ! So don’t ask me.,

Overview -

W32/Fujacks!htm is a detection for the following type of files infected with the parasitic W32/Fujacks virus:
- htm
- html
- asp
- php
- jsp
- aspx

When infected, these type of files will act as a downloader when executed and download the W32/Fujacks virus.
Characteristics
Characteristics -

These type of infected files:
- htm
- html
- asp
- php
- jsp
- aspx

When executed by a browser, will download in background a variant of W32/Fujacks parasitic virus, which will infect the following files:
- EXE
- SCR
- PIF
- COM

and the already cited types above.
When infecting the html,htm,asp,php,jsp and aspx files, it will append an iframe with width=0 and height=0, so the user will not notice it.
Symptoms
Symptoms -

The computer may become slow and may occasionally reboot due the infection of the executable files.
For the W32/Fujacks!htm infected files, they will have an iframe in the last line of the files.
Method of Infection
Method of Infection -

The W32/Fujacks virus will search several different vectors to find these type of files:
- htm
- html
- asp
- php
- jsp
- aspx
- EXE
- SCR
- PIF
- COM

So it can infect them.
Removal -
Removal -

A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.

Additional Windows ME/XP removal considerations
Variants
Variants -

N/A

5 Comments »

  1. vendan says

    today my computer automatically downloaded the trojan rar from the site http://crew.xbox-crew.net/JavaLOG.exe and tried to extarct the files into windows folder, time god nod32 prevented it. thanks to NOD32.This Happened when i browsed in imdb.com so becareful when visiting imdb

    August 10th, 2007 | #

  2. Marc says

    How is the virus related to imdb.com? Probably some other infection already on your machine.

    Ragha, you didn’t mention that you were the one who spread the virus to all the computers in your school.

    August 10th, 2007 | #

  3. Adithya says

    yes and to all our computers and din know how to remove them!

    August 11th, 2007 | #

  4. admin says

    Seems like Fujacks is getting a new face !

    August 11th, 2007 | #

  5. Arun says

    You tried too hard. Nobody made a reference to that. :mrgreen:

    August 19th, 2007 | #

Leave a comment

:mrgreen: :neutral: :twisted: :shock: :smile: :???: :cool: :evil: :grin: :oops: :razz: :roll: :wink: :cry: :eek: :lol: :mad: :sad:

RSS feed for these comments. | TrackBack URI

 

November 2007
M T W T F S S
« Oct   Dec »
 1234
567891011
12131415161718
19202122232425
2627282930  

Recent Posts

Categories

Recent Comments

Spam Blocked

Proudly hosted in AMPLI5