Go Back   Cyber Tech Help Support Forums > Software > Malware Removal

Notices

Malware Removal Discussion about Trojans, viruses, hoaxes, firewalls, spyware, and general Security issues. If you suspect your PC is infected with a virus, trojan or spyware app please include any supporting documentation or logs

Reply
 
Topic Tools
  #1  
Old December 21st, 2005, 02:07 AM
Pancake Pancake is offline
CTH Subscriber
 
Join Date: Jan 2004
Location: Australia
Posts: 11,317
WARNING on SANTA worm

A worm targeting the three major instant messaging (IM) networks is spreading its payload to buddy lists.
The IM.GifCom.All worm shows up as an innocuous-seeming URL in a chat message screen, featuring a link to what appears to be a Santa Claus site, said IM security vendor IMlogic, which first discovered the worm Monday.
In reality, clicking on the link starts a download that embeds a rootkit on the user's PC. The payload within the rootkit often goes by the name of gift.com, security experts at IMlogic said, and it immediately begins scanning the user's registry, file system and Internet cache.
The rootkit also contains a keylogger that records the keystrokes the user performs, generally used by malicious software writers to collect sensitive information such as credit card numbers, login information and passwords.
The malicious software also attempts to shut down the user's antivirus software and make several networking calls, possibly a repository maintained by the malware writer to collect keystroke information.
The worm may also try to propagate itself to the user's buddy list.
While IMlogic rated the IM.GiftCom.All worm as a medium risk, the worm is unusual in that it targets the three major public IM networks -- AIM, Yahoo IM and MSN Messenger -- as well as AOL's ICQ service. Most IM worms target one or two platforms at a time.
According to statistics maintained by IMlogic, MSN Messenger is the most popular platform for IM-based attacks, accounting for nearly 44 percent so far in 2005. AIM is second on the list at 26.5 percent.

The good news is that it is very Easily to protect from....Just dont click any links while on Im unless you know whom you are chatting to.
Reply With Quote
  #2  
Old December 21st, 2005, 10:48 PM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
CTH Subscriber
 
Join Date: Oct 2001
O/S: Windows Vista 32-bit
Location: New Zealand
Posts: 59,810
Thanks Pancake.
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Topics
Topic Topic Starter Forum Replies Last Post
PC has W32/Gaobot.worm.gen.u - Win32/RBot.3eu!Worm virus - need help removing asee Malware Removal 4 October 29th, 2009 02:27 PM
w32/Gaobot.worm.gen.u-win32/Rbot.3eu!worm MeYankee Malware Removal 13 July 29th, 2009 05:52 AM
I-Tunes email Java worm warning squiffy2 Malware Removal 0 February 14th, 2006 07:25 PM
Warning, New "Sonic Worm Virus" lufbra Open Discussion 9 November 2nd, 2000 10:53 PM


All times are GMT +1. The time now is 09:17 PM.