Add a virus spread through Yahoo! IM

Afternoon 1-8, a virus named VloveYM has spread to a series of computers in Vietnam. According to the analysis of the Network Security Center (BKAV), this virus appeared on July 28.

Like previous Gaixinh (Xrobot) and YMHeart viruses, VloveYM mainly spreads among Vietnamese people using Yahoo! Messenger.

Add a virus spread through Yahoo! IM Picture 1

When clicking on the link, the user will see a menu asking to download the Vlove file to the computer.

The new virus that appears and is spreading vigorously through Yahoo Messenger - we call it "VLove" temporarily (Calling the Vlove.exe file name of the virus link) - is distributed from a website with the address http:// /nguoiiu.com/funny/ .

If the computer is already infected with VloveYM, the virus will change its IE homepage to fun.nguoiiu.com . It is not possible to remove this homepage address, even if you change your home address or use spyware scanning programs. Next to those in the address book of this device will simultaneously receive links on the chat window like ' http . oiiu.com/funny/: D Funny via ne ', ' http . oiiu.com / funny / Do you want it, go to it =)) ',' http . oiiu.com / life / funeral ne =)) ',' http . oiiu.com / life / Tang ban tam thiep ne` . 'and will be thought of by your chat. It is the virus-infected person who does not know that he is spreading these dangerous links. If you click on it, the computer will be infected. These links immediately require users to download a virus file called " Vlove.exe ".

Immediately after having this information, VietNamNet contacted Bui Hai Nam - author of the Xrobots virus before. Nam affirmed that this is not his "masterpiece", but given the initial comment, it is likely that Vlove virus dispersers have used the source code of Xrobots written by Nam by reverse analysis (reverse) from the file. exe.

" In my opinion, this virus is also written in Autoit - this is the program I use to write Xrobots. Moreover, the source code is from the reverse Xobots.exe virus file is now spread quite a lot on the network. " - Nam confirmed.

However, according to our assessment, if we get the source code from Xrobots, Vlove has obviously been "improved". Evidence is that despite the Xrobots virus update, the latest anti-virus version of BKAV still doesn't kill Vlove. (Test conducted on 14h on August 1, 2006).

The BKIS Network Security Center said that they have now successfully analyzed Vlove and found the culprit to spread the virus. " It was a young man born in 1987 " - Mr. Nguyen Tu Quang - BKIS director said that along with the promise, he will update Vlove at the end of today in BKAV version.

Last night, BKAV updated this virus pattern in Bkav881 antivirus version. Users can go here to download or refer to how to kill this virus here.

4 ★ | 2 Vote

May be interested

  • Outbreaks of virus spread via fake emailOutbreaks of virus spread via fake email
    assuming an airline email, hackers are spreading dangerous trojans to users' mailboxes.
  • How to completely remove W32.UsbFakeDrive Virus on computer and USBHow to completely remove W32.UsbFakeDrive Virus on computer and USB
    the w32.usbfakedrive virus is a dangerous malware that can spread via usb and hide data. when users click on the fake shortcut, the virus will spread to the computer. to completely remove this threat, you need to use antivirus software combined with fixattrb bkav to restore hidden data.
  • 'Fight' with Vinatad'Fight' with Vinatad
    from yesterday (november 16) until now, despite being wary of the 'pandemic' virus spread through yahoo messenger, many people have been stuck with a temporary virus called vinatad! we would like to introduce an article about this new virus from the blog
  • Beware of MSN virus' hi. this is your photo? 'Beware of MSN virus' hi.  this is your photo? '
    for msn users, the virus spread through offline messages is very common. recently, a new virus has appeared in the form of this message
  • Facebook virus appearsFacebook virus appears
    this virus is spread via email, usually in the form of friends on your virtual social network inviting you to watch a video.
  • Covid-19 Room: Don't forget to dry your hands if you don't want your hands to become rubbishCovid-19 Room: Don't forget to dry your hands if you don't want your hands to become rubbish
    'disposable paper towels are recognized as the fastest and most effective way to remove residual moisture, which can create an opportunity for microorganisms to spread. this is very important in the context that people are concerned about the spread of corona virus'.
  • Viruses spreading files appear strong in AprilViruses spreading files appear strong in April
    in april, the virus spreads again and again in a number and speed spread faster after more than a year of absence. these viruses cling to internet worms, taking advantage of the spread of these worms to 'b & o
  • Keep your computer safe when attaching USBKeep your computer safe when attaching USB
    one of the most dangerous and popular viruses on usb is the autorun virus and the hidden virus folder. with the autorun virus, every time you double-click the usb drive icon in my computer, the virus will immediately spread to the computer, causing many system errors.
  • The fake IE 7 virus appearsThe fake IE 7 virus appears
    if you receive an email asking you to download internet explorer 7 beta 2, delete it immediately. because it was just a virus that appeared and spread by forging the latest version of microsoft's browser test.
  • The first virus in PSPThe first virus in PSP
    security firm symantec has issued a warning about a new virus in sony's playstation portable (psp) handheld game device. however, trojans called pspbrick have a high level of risk and spread.