- Related Stories
-
New worm targets Apple chat users
February 16, 2006 -
Study: Instant-messaging attacks rose in 2005
January 10, 2006 -
Santa IM worm hits AOL, MSN and Yahoo
December 20, 2005 -
New IM worm chats with intended victims
December 6, 2005
The worm, dubbed "yhoo32.explr" by FaceTime Security Labs, was found two weeks ago on the Yahoo instant messaging network and was still active as of Friday, Tyler Wells, senior director of research at FaceTime, a seller of instant messaging security products, said in an interview.
The worm drops the "Safety Browser" on the target's machine. The rogue browser uses the same icon as Microsoft's IE Web browser and, when opened, takes users to a site that installs spyware on the PC, FaceTime said. "This is the first recorded incidence of malware installing its own Web browser on a PC," the company said in a statement.
The pest also sets the victim's IE home page to Safety Browser's Web site and plays looped music that cannot be stopped, FaceTime said. Additionally, when installed the worm sends itself to all of the infected user's contacts, the security company said.
The new threat arrives as a link in a message box on the target's PC. The link may also say "Goat_Ensem Bot" with a smiley. After someone clicks the link, at least one warning will be displayed to tell the user that software is about to be downloaded or installed and that this may be malicious, Wells said.
Researchers at Foster City, Calif.-based FaceTime discovered the pest after it hit on one of their test machines. These PCs are connected to instant messaging networks and typically logged in to chat rooms, which often are the starting point for new IM worms.
IM users can protect themselves against this and many other IM threats by not clicking unexpected or unsolicited links.
See more CNET content tagged:
FaceTime Communications, IM, Web browser, worm, Yahoo! Inc.







______________________________
R.K.
http://www.Remove-All-Spyware.com
- simple final fix
- by CaptDave86 May 30, 2006 5:26 AM PDT
- a simple fix for all non-link based IM viruses is to ditch the client from Yahoo/AIM/MSN and get Trillian. its that simple. now you cant prevent stupidity like everyone was saying, where someone will click on the link. but what are you going to do? Ill admit it, i had clicked on a link, where the text before it stated: "how is this for a Myspace profile picture? and a link after it, that was stated as a jpg file, whne i clicked on it, IE tryed to DL a DAT file, well nothing on my computer defaults to open a DAT. so i got a little curious and wanted to open it up in notepad to see if it was a compiled DAT or a scripted DAT, and unfortunatly it was compiled and i couldnt see and of the code. i dont have a decompiler so i couldnt figure out how it worked.
- Like this Reply to this comment
-
(16 Comments)But still, Trillian is the best approtch to getting rid of the nasty IM infested non-link viruses. i have been useing it for the last 6-7 years and never, ever have gotten infected with a IM based virus from it.