Live Messenger Virus: look at my summer pictures
Filed in: Microsoft, Security — July 25th, 2007
To all MSN Messenger or Live Messenger users, DO NOT accept “summer2008.zip” file from your friends! It is a worm virus!
I received strange message from my two MSN friends (both girls) that say “look at my summer pictures http://___.tripod.com/summer2008.zip” (subdomain hidden). I downloaded the zip file and extract. It appears to be an executable .scr file (default file extension for Windows screensaver).
OK, that’s fishy. It should be JPG or some other image formats. Although, SCR is default file extension for screensaver but many virus/worm also use the same extension to cheat the victims. I can confirm that the file is a worm/virus. I deleted the zip file and send a message to alert my friends, but they did not response.
My msn friends kept sending the messages randomly such as:
A photo with me and my best friend :$ !!
look at my sexysummer pictures http://___.tripod.com/summer2008.zip
Look how wasted Paris Hilton is, after she got jailed : (
This is me totaly naked :-O please dont send to anyone else
About “summer2008.zip” virus
After digging the Internet, I found a detail information page about the
summer2008.zip worm or known as IRC-Worm.Win32.Agent.a (Backdoor.Win32.IRCBot.acd) by Kaspersky Anti Virus. The virus sends random messages in different languages such as English and Chinese.
Upon execution of the worm (.scr file), it drops random file name in your Windows folder:
images0XX.zip
photos0XX.zip
albumXX.zip
photoXX.zip
pictures0XX.zip
pictureXX.zip
(XX is random digitals, such as album39.zip, images091.zip.)
How to remove summer2006.zip virus
I suggest you update your anti virus and do a full system virus scan, or ask an expert friend to remove the virus manually. The manual removal instruction is available at C.I.S.R.T. – Chinese Internet Security Response Team


