Skip the navigation

Viruses target IM

By Liane Cassavoy
May 5, 2004 12:00 PM ET

PC World - When it comes to viruses and worms, e-mail gets all the attention, but now that instant messaging has infiltrated both home and office, it too has become an attractive and easy target for virus writers.
From 2002 to 2003, worms and viruses that spread via IM and peer-to-peer networks increased 400%, according to Symantec Corp.'s Internet Security Threat Report. Already this year, we've seen the Jitux.A and Bizex worms targeting MSN Messenger and ICQ, respectively.
Jitux.A spread itself by tapping users' IM contacts, but Bizex had more malicious intent: It sent you a link to a Web site that scanned your PC for data on your electronic payments and finances. The site was quickly shut down once the worm was discovered, but no one is sure how much data was collected before then.
Expect the threats to continue. As users get more adept at stopping traditional attacks, virus writers will look for softer targets, says Bill Adler, president of CyberScrub LLC, a PC security software vendor. "Instant messaging, for many reasons, is a softer target."
But don't scrap your IM client just yet. Because most IM viruses and worms can't propagate automatically -- they require you to click a link or download an applet -- you can avoid many of the threats if you practice safe computing (see below).

No buddy of mine
Steve Sanders, a student at the University of California at Berkeley, learned this safety lesson the hard way. He was reading a buddy's profile on AOL Instant Messenger when he saw a message that read, "I can't believe I found (Sanders's screen name) picture here. HAHAHA," with a hyperlink to take him to a site where he could view the photos. Sanders clicked the link and agreed to download the "necessary" applet to view the photos.
"I'm usually more careful than that," Sanders said, but the site "looked legitimate, and ... it was directed right at me, so I installed the software."
The site had no photos of Sanders; instead it held the Buddypicture.net Trojan horse, which would have installed adware and spyware onto his PC and distributed itself by placing its link in his AIM profile. Luckily, his antivirus software caught it.
Another prime example is the Osama Found game, which circulated rapidly via AIM earlier this year. It spread by sending a link to AIM users, inviting them to download a game in which they could pretend to catch bin Laden. Users who clicked got the game -- as well as BuddyLinks, a program that

Reprinted with permission from PCWorld.com. Story copyright 2010 PC World Communications. All rights reserved.

Security

Additional Resources
Advancing Knowledge Sharing with Google: The LSNC Story
WEBCAST
In the modern work environment, knowledge sharing has become paramount to organizational success, given the geographic dispersion, mobility, and information overload. During this session, Legal Services of Northern California (LSNC) will discuss their recent knowledge sharing transformation. With employees across 14 offices, servicing one-third of California, and having to access information across a million documents, the challenge was daunting. To address this, LSNC tapped Google's expertise on enterprise search and cloud computing, and deployed a knowledge-content system.
Cost-Effective Virtualization Security
WHITE PAPER
Trend Micro(tm) Virtualization Security solutions deliver advanced security software to protect operating systems, applications and data on virtual and cloud servers to help ensure compliance, while allowing higher server consolidation rates, and maximizing performance and operational flexibility. With Trend Micro software deployed on your physical servers and virtual machines, your IT infrastructure receives comprehensive and integrated protection.
The Laptop Dilemma: How to Maximize Productivity and Lower the Burden on IT
WHITE PAPER
New era of mobile computing creates opportunities for remote productivity while next-generation, industry-standard technologies address management and data security. Read more in this white paper.
Security White Papers
Backup and Disaster Recovery eGuide
As the digital universe grows beyond imagination, enterprise IT executives face the daunting task of keeping their little pieces of it backed up...
Forrester Research: Know your Facts: Understanding The Realities Of Desktop And Application virtualization
Read Now.
Windows 7 Migration Made Easier with Desktop Virtualization
Read Now.
Virtualization 2.0: The Desktop Revolution
Read Now.
Securing Data in the Cloud
This document is intended to give a broad overview of our security policies, processes and practices.
All Security White Papers
Security Webcasts
Desktop virtualization keys innovation drive
View now.
Survival Guide: Overcoming the Obstacles to Effective Risk Management
This virtual meeting for IT managers and CIOs is based on a new IBM study. Senior Vice Presidents and a Chief Technology Officer...
The Evolution of Managed File Transfer
Managed file transfer has evolved greatly from its earliest meaning of scheduled FTP to today's meaning of complete file governance, including visibility, enforcement,...
How to cut software management costs and avoid over-spending in the future
View now!
Get a $20 Amazon Gift Card - Just watch a Demo
View now!
All Security Webcasts
IT Jobs