Beware of a worm spreads through instant messenger

UPDATED:

:hehe: To make your life easy, you can download a removal tool (thanks to Matrixalaya and YoTsi) to KILL this worm and remove related files.

————————————————————

Yesterday, I received a zip file without given second thought from my Window Live Messenger, then, I unzip the file and worst was I activated it. Immediately after that, my computer was infected by a worm.

This is how the worm spreads through MSN or Window Live Messenger.

After infected by that nasty worm, it will send out the file “img807.zip” together with messages look very curious to other contacts who currently on-line from your MSN or Window Live Messenger contacts list automatically. The other contacts will thought you are the one send out this file.

The messages send together with the file are as below

Did you take this picture?
Is that you on the left?
How drunk was I in this picture?
Is that your mom in this picture?
lol, your mom just sent me this picture?

The .zip file contains a .com file “img807.jpg-www.photoalbums.com”, which actually is Win32.Backdoor.IRCBot (Lavasoft definition) or Backdoor.Win32.IRCBot.zi (Sophos definition).

When it is activated it will creates a file in Drive C:

C:\windows\vpcrtf.exe

Besides, it will creates a registry entry too

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Microsoft Visual Application”=”vpcrtf.exe”

How to remove it? I learned this method (thanks to friend of mine in Japan, Shipng) after I spent my whole day to reformat my computer (#¤%&@%¤#@)

Delete the registry entry first:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
“Microsoft Visual Application”=”vpcrtf.exe”

and then restart your computer, and delete the files at Drive C:
%windows%\vpcrtf.exe
%windows%\img807.zip

However, I would like to suggest you scan your computer again with Ad-Adware SE after you have done that (if you are unlucky as me).

TechTags Plugin [ | | | | | ]

   3 Responses to “Beware of a worm spreads through instant messenger”

  1. The Malaysian Blogosphere » Blog Archive » Journeying: Beware of a worm spreads through instant messenger Says:

    [...] The messages send together with the file are as below (more…) [...]

  2. 宝贝 Says:

    dun understand y ppl like spread virus everywhere leh? @.@

    KJ: Me either.

  3. YoTsi Says:

    I was also caught by that virus after googling I found a removal tool at
    http://matrixalaya.blogspot.com/2007/08/img807zip-or-msnpoopy.html

    KJ: Thanks for your information

   Leave a Reply