Home Malware Programs Worms IM.Worm.VB.as

IM.Worm.VB.as

Posted: January 11, 2010

Threat Metric

Threat Level: 9/10
Infected PCs: 84
First Seen: July 24, 2009
OS(es) Affected: Windows

IM.Worm.VB.as is a malicious computer Worm which spreads through unpatched security vulnerabilities and via instant messages (IM). The spyware sends bogus messages containing links to malicious files to all the contacts in the victim's buddy list. Once the user follows such a link, IM.Worm.VB.as is silently downloaded onto the computer. IM.Worm.VB.as comes with a rootkit that hides all harmful processes and files from most antivirus tools. IM.Worm.VB.as's payload is comprised of several malicious functions.

First of all, the worm disables some Windows essential components and terminates running antiviruses and security-related applications. Then it runs a backdoor component, which provides the attacker with unauthorized remote access to the compromised PC. The intruder can log user keystrokes, set up a hidden FTP server, intercept network and Internet traffic, contact specified web resources and steal user sensitive information. IM.Worm.VB.as can also change the web browser's default home page and download a variant of the Sdbot worm. The threat automatically runs as a service on every Windows startup. IM.Worm.VB.as must be removed from the compromised system once detected.

Aliases

Mal/VB-A [Sophos]Suspicious file [Panda]W32/Generic.d [McAfee]IM-Worm.Win32.VB.as [F-Secure]Worm.VB.as [eWido]Win32.VB.as [eSafe]Win32.HLLW.Xorut [DrWeb]Win32.Worm.Vb.Reaw.A [BitDefender]Worm/VB.AMM [AVG]Win32:VB-CWS [Avast]Worm/VB.Reaw.A [AntiVir]Win32/Xema.worm.61440.J [AhnLab-V3]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



Win.exe File name: Win.exe
Size: 25.08 KB (25088 bytes)
MD5: d0220483ac5a573a6bf226dfc12e8c39
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
Loading...