MSN.COM - W32.Spybot.Worm in the wild
There appears to be some malware in the wild. I received a MSN note from one of my MSN Contacts this afternoon. The FQDN for the link was gallery.aokhost.com and the link includes my MSN e-mail address and it has a sentence about "Hey, is this really your pic?" or a similar phrase. The URL includes a PHP script and the users MSN contact (username@domain.com). It appears the PHP script loads the malware and the user Contact is used only to lure you to click the link. The malware is dumped to C:\Windows\msn.com on my Windows XP Pro system.
I am running Symantec Endpoint Protection 11 with current virus definitions. It appears to have run once, then SEP11 quarantined it, but a system restart was required to fully remove it from my system.
It does not appear that any other damage was done to my system other than hitting my Contacts and spawning the IM's to everyone on my list.
Symantec Corp Edition 10.1 with current virus definitions will remove the infected file after a system restart. The Symantec link is below and they have a whole page of remediation tools for W32 malware.
http://www.symantec.com/security_response/writeup.jsp?docid=2003-053013-5943-99

