W32.Spotface.A


Aliases: N/A
Variants: N/A

Classification: Malware
Category: Computer Worm

Status: Active & Spreading
Spreading: Slow
Geographical info: Asia, North and South America, and some parts of Europe and Australia
Removal: Easy
Platform: W32
Discovered: 14 Feb 2007
Damage: Medium

Characteristics: The W32.Spotface.A application is a worm that multiplies through the Instant Messenger of MSN. It also downloads a duplicate of Backdoor.IRC.Bot on the computer.

More details about W32.Spotface.A

The W32.Spotface.A program is a worm that multiplies through the Instant Messenger of MSN. It also downloads a duplicate of Backdoor.IRC.Bot on the computer. The W32.Spotface.A worm may attack on to the compromised PC as “crsss.exe” file. Then the worm searches for and ends the “taskmgr.exe” process. After that, the W32.Spotface.A waits for “MSN Messenger” and “MSN Live Messenger” Instant messenger clients to become active.

The worm the spreads out the messages like "Heeey! I found a picture of you online, Haha look at your face” and “[http://]www.viotagallery.com/PIC/DATA/14/PartyG/picdo[REMOVED]” to messenger of the list of buddy. The present file at this location is a duplicate of “Backdoor.IRC.Bot”, which could be utilized to execute and download a duplicate of the worm. The W32.Spotface.A stops the process once the needed numbers of messages have been spread out. Then the worm deletes itself.