NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Windows Live

Windows Live


New Worm Attacks Windows Live Messenger - Seeds Itself via BitTorrent

And breaks up bootnets harvesting bots

By Marius Oiaga, Technology News Editor

25th of June 2007, 09:43 GMT

Adjust text size:


Windows Live Messenger
Enlarge picture
W32/Impard-A is everything but the kitchen sink type of malware. Security company Sopos revealed that W32/Impard-A is essentially a worm targeting the Windows platform (Windows Vista is not mentioned particularly) also featuring IRC backdoor capabilities. The worm spreads via either Windows Live Messenger, AIM or an eventual BitTorrent application on the compromised computer. Richard Cohen, security expert with SophosLabs CA revealed
that the worm comes with multi-lingual support and is pushed through a social engineering scheme.

"It's controlled by a remote user over IRC, and is capable of sending itself via AIM and MSN, storing itself as a file called IMG009.jpg-www.imagehosting.com inside a zip file called C:RECYCLERmyphoto.zip, and then sending this zip with a message that promises pictures, written in the same language as the infected computer. This sort of social engineering tries to maximize the chance that recipients will believe it to be legitimate and open the attachment, though this is shot in the foot somewhat by the fact that many of the the phrases have been cut off abruptly," Cohen stated.

The promise of the sender's photos is nothing more than an incentive to execute the malformed file in order to catalyze the infection. Once on an infected machine, W32/Impard-A can also start seeding itself through BitTorrent. The worm itself will initialize a torrent to a chosen location if it detects a "bittorrent.exe" file on the infected computer. Sophos also informed that the worm will detect and remove alternative bots on the computer.

"It scans through each running process and looks for signs that it might be a bot. If any catch its attention, it first attempts to terminate that process, then to send the file over IRC to its own controller, and finally to delete it. This clean-up isn't for altruistic reasons, but sees the author staking the infected computer as his territory, while also sending himself the offending bot to add to his own personal arsenal," Cohen added.

TAGS:

Windows Live Messenger | Sophos | Windows | worm
Read by 3,376 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.6/5) 8 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Windows Live Messenger - Happy Birthday!

Microsoft Leaks the Upcoming Windows Live Messenger 8.5

Preview the New Windows Live Messenger 8.5

The New Windows Live Messenger 8.5 Beta for Vista - Download Now!

Symantec Warns of Windows Live Messenger Adware

Windows XP Service Pack 3 Leaked Details!

2 Fresh New Windows Live Messenger Worms Wreak Havoc - Vista Not Affected

Windows Live Writer Beta 2 Available for Download

Throw Outlook Express and Windows Mail Away. Windows Live Mail Is Here!

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM