New kid on the block WORM_SPOTFACE.A is inching its way into computers as it spreads via MSN Messenger and Windows Live Messenger dressed in these drabs:
“heeey! i think i saw your picture online :O
hahaha that’s you right? 😀
Once installed on a system, it delivers the canned IM above to 50 contacts in the infected user’s instant messaging list.
Eventhough the mentioned URL is unavailable as of this writing, SPOTFACE’s other routine is a big enough nuisance. It deletes all the executable files found in a user’s root folder. It also has the intriguing routine of terminating NVSCV32.EXE , a process associated with the current it girl of malwareland, FUJACKS. Is the time of worm wars really long past or do we smell one coming?