Beware of a worm spreads through instant messenger
UPDATED:
To make your life easy, you can download a removal tool (thanks to Matrixalaya and YoTsi) to KILL this worm and remove related files.
————————————————————
Yesterday, I received a zip file without given second thought from my Window Live Messenger, then, I unzip the file and worst was I activated it. Immediately after that, my computer was infected by a worm.
This is how the worm spreads through MSN or Window Live Messenger.
After infected by that nasty worm, it will send out the file “img807.zip” together with messages look very curious to other contacts who currently on-line from your MSN or Window Live Messenger contacts list automatically. The other contacts will thought you are the one send out this file.
The messages send together with the file are as below
Did you take this picture?
Is that you on the left?
How drunk was I in this picture?
Is that your mom in this picture?
lol, your mom just sent me this picture?
The .zip file contains a .com file “img807.jpg-www.photoalbums.com”, which actually is Win32.Backdoor.IRCBot (Lavasoft definition) or Backdoor.Win32.IRCBot.zi (Sophos definition).
When it is activated it will creates a file in Drive C:
C:\windows\vpcrtf.exe
Besides, it will creates a registry entry too
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Microsoft Visual Application”=”vpcrtf.exe”
How to remove it? I learned this method (thanks to friend of mine in Japan, Shipng) after I spent my whole day to reformat my computer (#¤%&@%¤#@)
Delete the registry entry first:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
“Microsoft Visual Application”=”vpcrtf.exe”and then restart your computer, and delete the files at Drive C:
%windows%\vpcrtf.exe
%windows%\img807.zip
However, I would like to suggest you scan your computer again with Ad-Adware SE after you have done that (if you are unlucky as me).
TechTags Plugin [ worm | trojan | Win32.Backdoor.IRCBot | Backdoor.Win32.IRCBot.zi | img807.jpg-www.photoalbums.com | img807.zip ]



August 14th, 2007 at 11:14 pm
[...] The messages send together with the file are as below (more…) [...]
August 15th, 2007 at 4:19 am
dun understand y ppl like spread virus everywhere leh?
KJ: Me either.
August 15th, 2007 at 7:57 am
I was also caught by that virus after googling I found a removal tool at
http://matrixalaya.blogspot.com/2007/08/img807zip-or-msnpoopy.html
KJ: Thanks for your information