Fizzer Worm Uninstalling Itself
boredMDer writes "According to a recent update on the Dshield.org mailing list, apparently the Fizzer Task Force has gained control of the Geocities webpage from which Fizzer updates itself. From an IRC-Security mailing list: 'We have also postted a Fizzer cleaner to the actual URL that the bot downloads its updates from, as a self extracting and running executable.' The Fizzer-uninstaller posted there creates the file '%WinDir%\uninstall.pky', which then causes Fizzer to remove all of its registry keys. Looks like the Fizzer worm will soon come to an end."
This could be applied to another virus: Windows.
1. Hack the "secure" automatic update system.
2. Add/modify critical update.
3. Have said update uninstall Windows when executed.
3. Wait for machines to update themselves and auto-destruct.
4. ???
5. Profit.
This post is free (as in cheese in a mousetrap).