New IM worm infects AOL software
IDG News Service -
Users of AOL's instant messaging software, AIM, should be on the lookout for an innovative new worm variously named "Oscarbot-B" and "Doyorg" by antivirus companies.
The Windows-based malware emerged last week, and has made itself a nuisance for its ability to hijack the list of contacts or "buddies" in an infected user's IM account. After opening a window to any one of these contacts with the message "Hey check this out," it invites users to follow an embedded link. Anyone who clicks on this will risk becoming its next victim.
On machines where infection is successful, the worm creates a backdoor into Internet Relay Chat to download and run files on the instruction of the attacker, giving remote access to that PC.
Intriguingly, the attempt to spread via AIM is not initiated immediately, and depends on a further instruction from the attacker to start the infection/attack cycle anew. This might explain why the infection cycle has thus far moved slowly without being widely commented on by antivirus companies.
Although its effects are little worse than a nuisance right now, in the world of malware that counts for nothing.
Graham Cluley of Sophos, an antivirus company that targets business customers, suggested that companies needed to consider whether IM is worth the risk.
"Fundamentally, many businesses will have to ask their staff if they really need IM for their day-to-day work ,and if not, it may be more sensible to take it away," he said. "We're certainly seeing more instant messaging malware being written, although they haven't yet had the same kind of impact as email-aware worms or Internet worms."
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....
Why Now is the Right Time for the Linux Desktop
(Source: Novell) Faced with tighter budgets, enterprises are rethinking their desktop strategies to deliver the same - if not better - services and...
Moving Beyond Monolithic - What's Next for Enterprise Application Architectures?
This white paper reviews the current state of enterprise application architecture and presents a prediction on what might come next....
Novell Opens PR Video
Is the Linux desktop for me? Customers are looking for ways to be more flexible and save money. Using Linux offers a great...
SUSE Linux Enterprise Server Deployment Approach Guide
This document is intended for IT professionals and managers who are considering deploying SUSE Linux Enterprise Server. Novell has had a number of...
Strategic ECM Webinar
Learn what new strategic business benefits can be realized through ECM!...
SUSE Linux Enterprise Desktop Data Sheet
SUSE Linux Enterprise Desktop is the market's only enterprise-quality Linux desktop ready. It delivers seamless interoperability with existing enterprise systems and dozens of...
Managing And Protecting Your Ever Increasing Mobile Assets
Learn best practices for desktop and application virtualization, computer security, and computer life-cycle management....
SUSE Linux Enterprise Server Data Sheet
SUSE Linux Enterprise Server is a highly reliable, interoperable and manageable server operating system built to power mission-critical workloads in physical and virtual...
5 Architecture Issues that Impact BES performance
This Live webinar will identify critical log file errors, performance counters, and configurations to pay close attention to when optimizing BES server performance....
Subscribe to Computerworld
