31 Oct 2005
Security researchers have identified a worm spreading through AOL's instant messaging client and chat rooms.
The rootkit file is being passed through instant messages from members on a user's 'buddy' list. Bundled with the previously identified W32/Sdbot-ADD worm, the lockx.exe rootkit file is installed when users click on the link within the IM window.
Although the worm is not new, this is its first appearance on AOL's AIM system. Even more concerning is that rootkits have not previously been spread via IM.
"This is the first instance of a rootkit coming through the IM vector," said Tyler Wells, senior director of engineering at FaceTime Communications.
FaceTime discovered the rootkit using honeypots monitoring IM networks, websites and chat rooms for malicious content and URLs.
The company said in a statement that the rootkit could give an attacker access to, and remote control of, the PC and could steal information or promulgate more viruses by using the PC in a 'bot' network.
W32/Sdbot-ADD seems particularly dangerous and can be passed along to users on the buddy list.
The rootkit can shut down antivirus software, alter the user's search page, push CPU usage to 100 per cent and automatically download unwanted programs such as 180Solutions, Zango, MaxSearch and others.
AOL said that it is looking into the problem.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Application Support Analyst with exceptional communication...
Software Development Manager- Rugby/Warwickshire - Attractive...
Working for a leading Retail organisation, you will be...
business analyst, tester, fixed income, fi, derivatives...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?