Worm with rootkit hits AOL chat service
A URL for the worm is passed through instant messages on a person's Buddy List
November 1, 2005 12:00 PM ETIDG News Service -
Links leading to a worm that eventually implants a nasty rootkit on a user's computer are popping up on America Online Inc.'s Instant Messenger network, security researchers said.
The URL is passed through instant messages on a person's Buddy List and in AOL chat rooms, Websense Inc. reported. Some versions of the URL have been taken down, and all were hosted on personal Web pages, the company said. Users see an instant message that says "see thing!!" or "hilarious," followed by a URL.
Clicking on the link starts a known worm, W32/Sdbot-ADD, which then transmits the lockx.exe rootkit, according to an advisory posted Friday by FaceTime Communications Inc., which is based in Foster City, Calif. The code allows an attacker to monitor the computer and upload or download files.
It also attempts to shut down antivirus programs in addition to installing a back door that could be used to install more software. The lockx.exe rootkit connects to an Internet relay chat server and waits for remote commands.
Additional annoyances include changing the home page on the user's Internet browser and downloading applications from vendors such as 180solutions, Zango, the Freepod Toolbar, MaxSearch, Media Gateway and SearchMiracle, FaceTime said.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Security
Additional Resources



White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

