|
|
|  |
|
|
|
|
F-Secure Malware Information Pages: Fujack.K

|
|
|
| Radar |
 |
|
|
|
Summary
|
Fujack.K is a virus and a network worm. It infects executable files with certain extensions by prepending its body to these files. It also infects webpages by appending an IFrame tag and a malicious URL to them. The worm actively spreads to external media, for example to USB drives or network drives. It attempts to perform a dictionary attack in order to break weak network share passwords. In addition, the worm kills processes belonging to anti-virus and security software as well as processes of the Task Manager and Registry Editor. The worm can download and run malicious files from a website. Fujack.K was possibly created by the author of the Viking virus-worm. |
|
|
|
Disinfection
|
Disinfection of the Fujack.K virus-worm should be performed as follows:
- Disconnect a computer or local network from the Internet.
- Disable network sharing or set strong passwords for all shares.
- Select the "Disinfect Automatically" action for F-Secure Anti-Virus real-time scanners on all computers. With "Disinfect Automatically" selected, F-Secure Anti-Virus will disinfect files that a virus tries to infect over a network (if sharing was not disabled).
- Scan all files on all drives on all computers and MANUALLY select the "Disinfect" action to disinfect all infected files and to rename the virus droppers. DO NOT select automatic disinfection option after the scan!
- Restart all disinfected computers.
- Scan all hard drives on disinfected computers again to make sure that no more infected files are left. If needed, repeat disinfection procedure.
- Disinfect all infected computers connected on the network.
- Enable network sharing, keep strong share passwords.
- Reconnect the disinfected computer or local network to the Internet.
Please note that because of the "Worm." detection prefix F-Secure Anti-Virus will suggest to delete infected files, but DO NOT select the "Delete" option because this worm also has a viral component and you don't want to delete all infected files instead of disinfecting them. At the same time, the worm's dropper and downloader files should be deleted from a computer to prevent re-infection. |
|
|
|
Detection
|
F-Secure Anti-Virus detects this malware with the following updates: [FSAV_Database_Version] Version = 2007-01-16_04.
|
|
|
|
F-Secure Corporation |
|
|
|
|
|
Last Modified: January 16, 2007
|
|
|
|
|