Main Menu
Home
Bookmark
Contact Us



 
I-Worm.Newpic. Viruses Information

Name: I-Worm.Newpic.
Category: Viruses
Description: Details
I-Worm.Newpic.a

This is a virus-worm that spreads via the Internet using MSN Messenger (instant messaging program). The worm itself is a Windows EXE file about 50Kb in length written in Visual Basic.
When an infected file is run, the worm dislays the following fake message:
Error
Cannot open file. May be corupted. Replace the file with a new
one and try again.
Then it registers itself in the auto-run registry key:
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun MSN Messenger = %filename%
where %filename% is the worm's full file name.
The worm then waits for incoming messages and replies with the following text:
hey, want me to send my new pic?
i took it yesterday
The the worm waits for an answer. If a user answers with one of following words:
sure
yes
yea
guess
ok
send
maybe
go
the worm sends its EXE file to a victim and then sends one of the following randomly selected texts:
alright, here ya go
i hope you like it
there
pweese? :)
ok cool
The worm also creates the "C:Messenger1324Brain1Read Me.txt" file and writes a text there:
I come in piece. My name is Jerry.
The purpose of me is to spread. I'm not annoying, nor dangerous.
How to remove me:
1) Click Start, select Run. The Run dialog box pops up.
2) Type: msconfig The System Configuration Utility pops up.
3) Click the Startup tab at the top. In the list, find MsgSprd, Messenger, or pic1324, uncheck, press Apply, then press Ok.
4) Restart your computer Or press Ctrl - Alt - Del, select MsgSprd from the list, then press End Task.
You may freely delete the files or the 'C:Messenger1324' directory.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Hammer.227
Crash.60
BAT.Sakur
Win95.Yildi
Hannibal.97
DataFire.108
Phx Famil
Macro.Word97.Save
Macro.Excel.Ne
Linux.Bliss.


 


© 2006-2008 spyware32.com - Privacy Policy