AntiyLabs
alarm

Alert: The large-scale outbreak of latest MSN Photos variant

2008-03-13

Antiy Labs CERT


 

March 13, 2008, Antiy Lab anti-virus inspect system intercepted a rapidly spread virus named
as (Backdoor.Win32.IRCbot.gen). MSN users would send lots of spam and virus to their friends
after the system was infected, and this virus sends compressed file named "MyPhotos94.zip".
Virus attack plans:

According to anti-virus experts' analysis from Antiy Labs, after the virus'execution,
it would automatically contact list of friends, say “I was so drunk at this party..
check it out lol” then try to send a compressed format, with the named information
like "MyPhoto"、"picture" in order to trick users to accept the document. Once users
open the file, the system will be infected. Besides, the virus also has backdoor function and hacker could carry out remote control.

Antiy anti-virus experts advise all users:
1. Please update your system by Microsoft automatic update service or program in time,
and install the patches.
2. Install professional anti-virus software, upgrade to the latest version, and run real-
time monitor.
3. Do not open the documents from the Instant Messenger software like QQ, MSN
before you confirm, and if the other side does not give responses, most likely the
virus is automatically sent.


Copyright © 2005 by Antiy Labs.
Permission to redistribute this alert electronically is granted as long as it is not edited in any way unless authorized by Antiy Labs.