
A new virus labelled a variant of the Win32/Spy.VB.LO trojan by NOD32 has been spreading via Windows Live Messenger over the past couple of weeks, one of the messages it typically sends contains the recipients e-mail address, looking something like this:
» rofl @ you, http://improfile.net/members.php?msn=example@example.com
The Web site has been shutdown to stop it from spreading. The DNS is set to loopback (127.0.0.1) and “Closed for Fraud” is in the whois information.
Kelvin has created a tool called impFix to remove the virus, so give it a try if you believe to be infected with this pest.

Thank you so much. have spent hours and hours doing virus scans to find it just kept coming back. You are a savior.
having had to format harddrives because of this virus - and yes i tried removing - i finally got hold of the sods details from the other domain name he has used to spread this virus
the other domain is http://www.im-profile.com
which is now being redirected to some charity!
HIS details are as follows
Domain name: im-profile.net
Registrant Contact:
Daniel Allberty
Daniel Allberty (allbertydan@yahoo.ca)
1.7153224409
Fax: 1.7153224409
N4801 County Rd B lot 16
Glen Flora, WI 54526
US
looks like he lives on a trailerpark!!
anyway his email adress can easily be submitted to spam companies and im sure someone will do that!
http://www2.imward.com/m.php?m=hoe_chin@hotmail.com those ur pics?
does ur tool fix this virus too?