Encyclopedia

MSNworm.GM

 
Threat LevelLow threatDamageHighDistributionNot widespread

Effects 

The main aim of MSNworm.GM is to spread itself via the instant messaging program MSN Messenger and affect as many computers as possible.

Infection strategy 

MSNworm.GM creates the file FXSTALLER.EXE in the Windows directory. This file is a copy of the worm.

Additionally, it creates another copy of itself called BURIM.EXE in the Windows temporary directory.

 

MSNworm.GM creates the following entry in the Windows Registry:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    Windows UDP Control Center = fxstaller.exe

    By creating this entry, MSNworm.GM ensures that it is run whenever Windows is started.

Means of transmission 

MSNworm.GM spreads via the messaging program MSN Messenger. In order to do so, it carries out the process below:

  • It sends an instant message enticing users to see a picture. This message contains a file which passes itself off as an image.
  • When the file is run, the following error message is displayed:



    The aim of this message is to deceive users making them think that there has been an error with the image.
  • However, a copy of the worm will be downloaded to the affected computer.
  • Then, it sends a similar instant message to all the users that are connected at that moment.

Further Details  

MSNworm.GM is 101,376 bytes in size.

Last updated:  16/06/2009 

Virus News

3/10/09.-More than 10 Million Worldwide Were Actively Exposed to Identity Theft in 2008

3/5/09.-Cyber-crooks manipulate Internet searches to sell fake antivirus products

3/2/09.-VideoPlay adware infections grew 400% in February through malicious use of Web 2.0 pages

[+ Noticias]