You're in: Panda Security > Home Users > security-info > about-malware > encyclopedia > overview
Active Scan. Scan your PC free
Panda Security Product Line 2012

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Encyclopedia GetVirusCard True 0

MSNworm.EI

 
Threat LevelLow threatDamageHighDistributionNot widespread

Effects 

The main objective of MSNworm.EI is to spread via MSN Messenger and affect as many computers as possible.

Additionally, it downloads the backdoor detected as IRCBot.BWB to the affected computer.

The variants belonging to the IRCBot family are designed to connect to several IRC servers and receive remote control commands, such as download files, update themselves and send information about the computer, among others.

Infection strategy 

MSNworm.EI creates the file REP38_D.EXE, in the subfolder Local Settings\Temp of the Documents and Settings directory of the user that has logged in.

This file belongs to the backdoor detected as IRCBot.BWB.

Means of transmission 

MSNworm.EI spreads via the instant messaging program MSN Messenger. In order to do so, it follows the routine below:

  • The user receives an instant message which contains a file.
  • When the file is run, the following image is displayed:

  • Additionally, it downloads a copy of the worm to the affected computer.
  • MSNworm.EI sends this message to all the contacts that are active at that moment.

Further Details  

MSNworm.EI is 103,380 bytes in size and it is compressed with Nullsoft Installer.