W32/Fujacks.z is a copied variant of the W32/Fujacks worm that infects PE and HTML files and spreads over network shares and removable devices. It might also attempt to download additional malware on the infected machine. This variant may also be detected as W32/Fujacks.gen.
|
Minimum DAT
4984 (2007-03-14) Updated DAT5159 (2007-11-08) |
Minimum Engine
5.1.00 File Length80,384 bytes |
Description Added
2007-03-13 Description Modified2007-03-13 |
-- Update March 13, 2007 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://english.eastday.com/eastday/englishedition/node20676/userobject1ai2680348.html
--
W32/Fujacks.z is a copied variant of the W32/Fujacks worm that infects PE and HTML files and spreads over network shares and removable devices. It might also attempt to download additional malware on the infected machine. This variant may also be detected as W32/Fujacks.gen.
When executed, it scans for filename(s) with the following extensions and prepend itself to PE file(s); or insert a malicious hyperlink to HTML-type files (W32/Fujacks!htm):
It drops a copy of itself and a DLL with randomized filename(s) into:
(Where %Windir% is the Windows folder; e.g. C:\Windows)
The DLL is injected and executed in the following running process(es):
and a registry key is created to autostart the EXE at bootup time:
When finished with these steps, it drops a hardcoded batch file into %Temp%\~Lying!.bAt to delete the original malware file:
@Echo Off
:tRy
DeL {filename} /A
iF ExiSt {filename} gOtO tRy
dEl %0 /A
clS
(Where %Temp% is the temporary folder; e.g. C:\Documents and Settings\{username}\Local Settings\Temp)
The injected DLL continues to scan for and attempts to access shared folders using weak passwords in the local area network. When successful, it can make copies of itself onto these shared folder using one or more of the following filename(s):
These files may have the following icon:

It may also download further malware from the following website(s):
At the time of writing, this URL is unavailable.
W32/Fujacks.z is a parasitic file infector that can spread over network drives and shared folders. It also has a downloader component that installs additional malware on the infected machine.
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).