You're in: Panda Security > Home Users > security-info > about-malware > encyclopedia > overview
Active Scan. Scan your PC free
Panda Security Product Line 2012

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Encyclopedia GetVirusCard True 0

MSNworm.GM

 
Threat LevelLow threatDamageHighDistributionNot widespread

Effects 

The main aim of MSNworm.GM is to spread itself via the instant messaging program MSN Messenger and affect as many computers as possible.

Infection strategy 

MSNworm.GM creates the file FXSTALLER.EXE in the Windows directory. This file is a copy of the worm.

Additionally, it creates another copy of itself called BURIM.EXE in the Windows temporary directory.

 

MSNworm.GM creates the following entry in the Windows Registry:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    Windows UDP Control Center = fxstaller.exe

    By creating this entry, MSNworm.GM ensures that it is run whenever Windows is started.

Means of transmission 

MSNworm.GM spreads via the messaging program MSN Messenger. In order to do so, it carries out the process below:

  • It sends an instant message enticing users to see a picture. This message contains a file which passes itself off as an image.
  • When the file is run, the following error message is displayed:



    The aim of this message is to deceive users making them think that there has been an error with the image.
  • However, a copy of the worm will be downloaded to the affected computer.
  • Then, it sends a similar instant message to all the users that are connected at that moment.

Further Details  

MSNworm.GM is 101,376 bytes in size.