On mySimon: Body Solid EXM 3000LPS
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Oct 28, 2005 9:33:00 PM

A worm found spreading via America Online's Instant Messenger is carrying a nastier punch than usual, a security company has warned.

The unnamed worm delivers a cocktail of unwanted software, including a so-called rootkit, security experts at FaceTime Communications said Friday. A rootkit is a tool designed to go undetected by the security software used to lock down control of a computer after an initial hack.

"A very nasty bundle is downloaded to your machine" when you click on the worm link, said Tyler Wells, senior director of engineering at FaceTime. "This is the first time that we have seen a rootkit as part of the bundle of applications that is sent to your machine. It is a disturbing trend."

Resource center
Identity theft
Experts debate key issues in ID fraud. Get the latest information here.

IM worm and malicious code attacks are happening more than ever before. The number of threats detected for instant-messaging and peer-to-peer networks rose 3,295 percent in the third quarter of 2005, compared with last year, according to a recent report from security provider IMlogic.

In addition to the "lockx.exe" rootkit file, the new worm delivers a version of the Sdbot Trojan horse, said FaceTime, which sells products to protect instant-messaging traffic. Sdbot opens a backdoor on the infected PC. The worm also places several spyware and adware applications, including 180Solutions, Zango, the Freepod Toolbar, MaxSearch, Media Gateway and SearchMiracle, the company added.

All that unwanted software can eat up system resources, slowing down the PC, Wells said. Also, the malicious applications will attempt to disable security programs and change the search page on the user's Web browser, FaceTime said.

The worm was spotted in an AOL IM chatroom and infected one of the PCs that FaceTime uses for worm bait. The company said it also has seen the pest hit other computers. "It is still out there, and it is definitely something the user should be leery of," Wells said. "The rootkit is designed to not be detected, and that is the scary part."

Worms on IM networks can spread rapidly. They appear as a message from a buddy with a link that looks innocent, but in fact points to malicious code somewhere on the Internet. Once the user clicks on the link, malicious code is installed and runs on the computer. The worm then spreads itself by sending messages to all names on the victim's contact list.

The advice to users is to be careful when clicking on links in IM messages--even when they seem to come from friends--and to use up-to-date antivirus software. When receiving a link in an instant message, the best practice is to verify with the sender if the link was sent intentionally or not.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 28 Talkback(s)
hey
wats up (Read the rest)
Posted by: xxchrisiixx Posted on: 12/28/06 You are currently: a Guest | | Terms of Use
This may not help.  Grayson Peddie | 10/28/05
No more links?  Immanuel Tranz-Mischen | 10/29/05
Great...anyone got a removal tool?  voyager529 | 10/29/05
It's easy.  Immanuel Tranz-Mischen | 10/29/05
Yeah, just throw out all the software you bought  Confused by religion | 10/30/05
No, my software isn't crap.  Immanuel Tranz-Mischen | 10/30/05
Re: Gnats  jbroche18 | 12/08/05
No  java.user | 10/31/05
Yes  Linux User 147560 | 10/29/05
Seriously Here ya go  Squawkbox | 10/30/05
Gee! What fun!  Immanuel Tranz-Mischen | 10/30/05
Re: Gee! What fun!  BXLE | 10/31/05
Thank you.  X Marks The Spot | 10/30/05
use AIM express  digitalrao77471@... | 10/29/05
AIM express???  horusfalcon | 10/31/05
fun  pimpgirl | 11/29/05
fun  pimpgirl | 11/29/05
fun  pimpgirl | 11/29/05
fun  pimpgirl | 11/29/05
hey  xxchrisiixx | 12/28/06
antivirus  CobraA1 | 10/30/05
Antivirus tools  X Marks The Spot | 10/30/05
Antivirus tools  X Marks The Spot | 10/30/05
This one has been keeping me busy  zmud | 10/31/05
AOL'rs Die! Die! Die!  An_Axe_to_Grind | 10/31/05
There's a market  archerjoe | 10/31/05
AOL'S AIM worm  rathersailawa@... | 11/19/05
AOL'S AIM worm  rathersailawa@... | 11/19/05

What do you think?

advertisement
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Save time with automated shipping solutions
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Visit the UPS Business Essentials Guide
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
advertisement

White Papers, Webcasts, and Downloads