In order to participate in the GunBroker Member forums, you must be logged in with your GunBroker.com account. Click the sign-in button at the top right of the forums page to get connected.
fyi: IM Worm Installs Bogus Browser
HAIRY
Member Posts: 23,606
IM Worm Installs Bogus Browser
Malware that spreads via Yahoo Messenger also plays screeching music and hijacks IE's home page.
Jeremy Kirk, IDG News Service
Monday, May 22, 2006
Malware writers have created a new worm that installs a new browser and plays screeching music.
The annoyance starts with a link apparently sent by a friend in Yahoo's instant messaging program.
Instant messaging security company FaceTime Communications described the malware, which it calls "yhoo32.explr", as "insidious" in a security advisory.
When the link is clicked, a worm installs the so-called "Safety Browser," a program that leads the user to pages mined with adware and viruses, FaceTime said. The Safety Browser uses an Internet Explorer logo to make it look more legitimate.
New Type of Attack
Malware spread through instant messaging programs is on the rise. However, FaceTime said this malware appeared to be the first to install a browser without the user's permission.
The bug also hijacks Internet Explorer's home page, directing users to the Safety Browser's Web site.
After it is launched, the worm sends itself to others on the user's instant messaging contact list.
The malware is engineered to overwrite instant messages typed by a user, FaceTime said. The infected message can also be changed on-the-fly, the company said.
The screeching music, however, is blocked by Microsoft's Windows XP Service Pack 2, FaceTime said.
FaceTime has posted screenshots of the infection process on its blog.
Malware that spreads via Yahoo Messenger also plays screeching music and hijacks IE's home page.
Jeremy Kirk, IDG News Service
Monday, May 22, 2006
Malware writers have created a new worm that installs a new browser and plays screeching music.
The annoyance starts with a link apparently sent by a friend in Yahoo's instant messaging program.
Instant messaging security company FaceTime Communications described the malware, which it calls "yhoo32.explr", as "insidious" in a security advisory.
When the link is clicked, a worm installs the so-called "Safety Browser," a program that leads the user to pages mined with adware and viruses, FaceTime said. The Safety Browser uses an Internet Explorer logo to make it look more legitimate.
New Type of Attack
Malware spread through instant messaging programs is on the rise. However, FaceTime said this malware appeared to be the first to install a browser without the user's permission.
The bug also hijacks Internet Explorer's home page, directing users to the Safety Browser's Web site.
After it is launched, the worm sends itself to others on the user's instant messaging contact list.
The malware is engineered to overwrite instant messages typed by a user, FaceTime said. The infected message can also be changed on-the-fly, the company said.
The screeching music, however, is blocked by Microsoft's Windows XP Service Pack 2, FaceTime said.
FaceTime has posted screenshots of the infection process on its blog.