Virus.PHP.Redz

Aliases
Virus.PHP.Redz  ( Kaspersky Lab ) is also known as: PHP/Redz ( McAfee ),   PHP.Redz ( Symantec ),   PHP/Redz ( Sophos ),   PHP/Redz* ( RAV ),   PHP_REDZ.A ( Trend Micro ),   PHP/Redz ( H+BEDV ),   PHP/Redz.A ( FRISK ),   PHP.Redz.A ( SOFTWIN ),   PHP.Redz ( ClamAV ),   Univ.A ( Panda ),   PHP/Redz.A ( Eset )
Detection added Dec 30 2004
Description added Jul 18 2007
Behavior Virus

Technical details
This script virus infects files with a .php, .htm, or .html extension. It is 677 bytes in size. It is written in PHP.
Payload
When launching, the virus searches the current folder for files with a .php, .htm or .html extension. It searches the files for a string reading "redz.php". If it does not find this string, the virus will write its body to the end of the file, and cease running.
Removal instructions
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program: Update your antivirus databases and perform a full scan of the computer ( download a trial version of Kaspersky Anti-Virus).

 

HOME