I’ve stopped dissecting malware for a while (no time– I’ve got a life now), but this one has been running wild for about a week and infecting many of my friends. It seems to run in my social circle (this would make an interesting study; how do bots perpetuate in online social circles?)
C’mon. This is proof I’d do really well working at Symantec, you know? Read more of this post to see how I reverse engineered the bot in under 30 minutes.
To Clean
- Boot Windows into safe mode and do not run anything.
- Carefully go into “C:\Windows” and remove the “tmpie” folder which contains the payload.
- Optionally remove the registry key “HKLM,”Software\Microsoft\Windows\CurrentVersion\Run”,”iexplorer”,0,”%10%\tmpie\iexplorer.exe”"
- Reboot into normal mode.
- Change AIM password as well as all social networking passwords.
- Stop downloading shit like this. Check to make sure the domain is real before you click. Yep, take a second or two to actually look at the URL bar in your browser. Won’t hurt you.