virus protection

WORM_IMBOT.AC memory resident worm malware

Thursday, January 24, 2008

This memory-resident worm may be dropped by other malware or downloaded unknowingly by a user when visiting malicious Web sites.

It propagates via the popular instant messaging application, MSN Messenger. It does this by sending a message and a .ZIP file that contains a copy of itself to target contacts.

The message it sends may be any of the following:

• Did you see this picture, it's hilarious!!!!!
• Have I shown you this new picture of my cat :)
• Hey, check out this great photo from my trip to England

This worm also has backdoor capabilities. It connects to random TCP ports and executes the commands from a remote malicious user. It also terminates certain processes, if found running in memory.
posted by Mandy, 3:19 PM

0 Comments:

Add a comment