AplusWebMaster
Topic Starter
FYI…
- http://www.techweb.com/wire/security/172901356
October 28, 2005
"A worm spreading through America Online's Instant Messenger (AIM) network carries a dangerous rootkit, code designed to hide a hacker's work from anti-virus scanners, a security firm warned Friday. Sdbot.add, said instant messaging security vendor FaceTime, includes the "lockx.exe" rootkit… If the AIM-running machine is infected, Sdbot.add gives the attacker control of the PC, lets him load additional software on it, and tries to disable installed security programs. It may also drop a slew of spyware and adware on the system, including programs from 180Solutions, Zango, and MaxSearch. Like all IM-based exploits, this worm spreads by hijacking contact names from the AIM buddy list, then sending messages to those people. A link in the message, if clicked, surreptitiously downloads Sdbot.add."
>>> http://www.facetime.com/pr/pr051028.aspx
"…New IM exploit launched through AIM, that:
* Adds a lockx.exe rootkit that connects to an IRC server, awaiting remote commands from an attacker. Rootkits may be used by an intruder after cracking a computer system and often hides logins, processes, files, and logs. It may include software to intercept data from terminals, network connections, and the keyboard
* Acts as a vector for additional adware, worms and viruses
* Changes a viewer’s original search page…
* Often increases the CPU usage to 100 percent after the malware is installed
* Downloads other applications, including 180Solutions, Zango, the Freepod Toolbar, MaxSearch, Media Gateway, and SearchMiracle…"

- http://www.techweb.com/wire/security/172901356
October 28, 2005
"A worm spreading through America Online's Instant Messenger (AIM) network carries a dangerous rootkit, code designed to hide a hacker's work from anti-virus scanners, a security firm warned Friday. Sdbot.add, said instant messaging security vendor FaceTime, includes the "lockx.exe" rootkit… If the AIM-running machine is infected, Sdbot.add gives the attacker control of the PC, lets him load additional software on it, and tries to disable installed security programs. It may also drop a slew of spyware and adware on the system, including programs from 180Solutions, Zango, and MaxSearch. Like all IM-based exploits, this worm spreads by hijacking contact names from the AIM buddy list, then sending messages to those people. A link in the message, if clicked, surreptitiously downloads Sdbot.add."
>>> http://www.facetime.com/pr/pr051028.aspx
"…New IM exploit launched through AIM, that:
* Adds a lockx.exe rootkit that connects to an IRC server, awaiting remote commands from an attacker. Rootkits may be used by an intruder after cracking a computer system and often hides logins, processes, files, and logs. It may include software to intercept data from terminals, network connections, and the keyboard
* Acts as a vector for additional adware, worms and viruses
* Changes a viewer’s original search page…
* Often increases the CPU usage to 100 percent after the malware is installed
* Downloads other applications, including 180Solutions, Zango, the Freepod Toolbar, MaxSearch, Media Gateway, and SearchMiracle…"