IM worm acts as a come on to a Santa Claus site



According to Information Week, there’s a new IM worm out hitting the MSN, ICQ, Yahoo and AIM networks. It poses as a come on for a Santa Claus site. On visiting the site, users receive an unexpected “present” a rootkit which is hidden.


IMlogic said that the worm, dubbed “M.GiftCom.All,” is circulating on the MSN, AOL, ICQ, and Yahoo instant messaging services, is a “Medium” threat, a relatively rare classification for the Waltham, Mass.-based company. Most IM worms and Trojans listed on its Threat Center receive only a “Low” classification.

Like virtually all IM worms, M.GiftCom.All includes a URL in messages it spams out to contacts hijacked from previously-infected PCs. When users naively visit that site — which is billed as a harmless Santa site — a file is automatically downloaded to their computers.

The file, usually named “gift.com,” includes rootkit elements that cloaks it from security software. In addition, the downloaded executable tries to disable a number of anti-virus programs, adds a keylogger to the system to capture confidential information, and then spreads to others by snatching names from the user’s IM client contact list.

So, watch what the young (and young at heart) click on this season and always.

More details at IMLogic.

Related Posts

Blog Traffic Exchange Related Posts
  • Major botnet building and the massive jump in spam For a few months now (since the demise of bluefrog actually) I've noticed that the level of junk mail has gone up on my own mail server. Yes, I use spamassassin to filter and tag, but the volume of stuff that's tagged has gone up (as well as the volume......
  • The press covering the WMF bug It's always a strange mix between comedy and frustration to see the main media outlets cover a tech news item. I usually wince and brace myself when I see any tv news outlet take on a computer issue and likewise when I read newspapers and non-tech publications take on anything......
  • How to Remove Virus Doctor (or Remove VirusDoctor) | Virus Doctor Removal It looks as though that Virus Doctor (or Virusdoctor) is an older rogue antivirus application, but since it seems related to the search I was seeing lot's of last night about rootscan.info I thought I would devote an article to the removal instructions for virus doctor. Since it may be......
Blog Traffic Exchange Related Websites
  • Download any .dll file that is Missing in Your Computer Well Folks, some of you might be facing problems related to .dll files. You can download missing .dll files from sites given below: DLL-files.com - Download all your missing dll-files. DllDump - free dll files. download dll files you need immediately! InfDump.com - download inf files you need immediately! OcxDump.com......
  • Having Your Bid On - Auctions Are Available It has benefited people that enjoy on-line shopping and enables them have opportunity to buy their favorite products below minimal charge. Unfortunately, buying goods through (bidding online) web sites has now become a possible danger. Given the significance of penny auction web sites on the web, there have come a......
  • Are Annuities the New Pension? I have thought and written extensively about the benefits, costs, and risks of immediate and variable annuities for retirement. Now even the White House is suggesting that more boomers consider using annuities to provide lifetime retirement income. In his State of the Union address, President Obama talked about economically supporting......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site