Quick Links: SpywareGuide Greynets Blog | SpywareGuide Product Database | SpywareGuide Company Database | SpywareGuide Categories
Search SpywareGuide Database & Site
Security Email Alerts & Updates
SpywareGuide powered by FaceTime Security Labs

Self-Propagating Worm Installs Unsafe "Safety Browser"

by FaceTime Security Labs

FOSTER CITY, CALIF — May 19, 2006 — Research experts at FaceTime Security Labs™ identified and reported a new threat today affecting Yahoo! Messenger. FaceTime researchers confirmed that a self-propagating worm, named yhoo32.explr, installs ‘Safety Browser’ and hijacks the Internet Explorer homepage, leading users to a site that puts spyware on their PCs. Because Safety Browser uses the IE icon, users can easily mistake it for Internet Explorer. This is the first recorded incidence of malware installing its own web browser on a PC without the user’s permission.

The self-propagating worm spreads the infection to all contacts in Yahoo! Messenger by sending a website link that loads a command file onto the user’s PC and installs Safety Browser. This spam over instant messaging (IM) is called spim. IM applications and protocols are an increasingly popular vector to distribute malicious files and executables.

pqnelhleyy ac1f1718 5a16c8f9

“This is one of oddest and more insidious pieces of malware we have encountered in years,” commented Tyler Wells, Senior Director of Research at FaceTime Security Labs. “This is the first instance of a complete web browser hijack without the user’s awareness. Similar ‘rogue’ browsers, such as ‘Yapbrowser,’ have demonstrated the potential for serious damage by directing end-users to potentially illegal or illicit material. ‘Rogue’ browsers seem to be the hot new thing among hackers.”

The India research arm of FaceTime Security Labs discovered the threat in a ‘honeypot,’ a trap they set to detect viruses, worms, spyware and other threats. Commentary on this threat by FaceTime Security Labs researcher Chris Boyd can be found on the Greynets Blog, at http://blog.spywareguide.com.  FaceTime Security Labs is the threat research division of IM and Greynet security leader FaceTime Communications.

Threat name: yhoo32.explr

Threat type: Browserware and worm

Who is affected: Users of Yahoo! Messenger

Additional Information: The malware infects the PC with two elements. The first element is a web browser called “Safety Browser.” This stand-alone application has no uninstaller and disguises itself with an Internet Explorer logo in some instances. The application also hijacks the personal homepage in Internet Explorer and points users to Safety Browser's homepage (demoplanet.tv). The hijack also plays looped music that cannot be stopped when the user starts up the PC or Safety Browser. The second element is the self-propagating worm. This worm installs an .exe file that spreads the infection through Yahoo Messenger to everyone on the Contacts List.

FaceTime Customers Are Protected Against This Threat
FaceTime’s RTGuardian and GEM customers are protected from this exploit if they have auto-update features enabled. FaceTime’s X-Cleaner customers should download the latest update and scan their PC.

FaceTime Enterprise Edition and IMAuditor customers can proactively block these malicious threats and prevent infections before they happen by utilizing the auto-update features to block downloads of the specific file types associated with the threats. FaceTime also recommends activating the Day Zero Defense System within IMAuditor 7.0. The system utilizes anomaly detection techniques to analyze multiple characteristics of IM-borne worms and other malicious code against normal behavior, and provides patent-pending protection against many IM threats – in addition to traditional security signatures.

About FaceTime Communications
Founded in 1998, FaceTime Communications is the leading provider of security solutions for the management and control of greynet applications such as adware/spyware, instant messaging, webmail, P2P file sharing, web conferencing and instant voice. FaceTime delivers the industry’s first IMPact Index, which assesses “point-in-time” risks posed by viruses, worms and other malware propagating through greynet applications. FaceTime's award-winning solutions are used by over 600 customers, among them seven of the eight largest U.S. financial institutions. FaceTime supports or has strategic partnerships with all leading public and private IM network providers, including AOL, Google, Microsoft, Yahoo!, IBM, Bloomberg, Jabber and Reuters.

FaceTime is headquartered in Foster City, California. For more information visit http://www.facetime.com or call 888-349-FACE.

Unless otherwise noted this article is Copyright © 2017 by FaceTime Communications, Inc. This article may not be resold, reprinted, or redistributed for compensation of any kind without prior written permission from FaceTime Communications, Inc. For reprint or media inquires please contact us with the phrase "Spyware Guide Articles" in the subject line and we will by happy to assist you. Links to this article from other websites are appreciated and encouraged. Users are also encouraged to utilize our RSS system to provide unique content and extracts for their site.

Read other articles (back to full list)

Help with the BUST!
Click here and give us what details you have and let our international research team take it from there. If you desire your report will remain anonymous.
Recent Blog Posts

There was an error communicating with the requested site.

Recent Modifications
2017-11-13  Adult Networks/Services
2017-2-10  Adult Hosts
2016-3-30  CoolWebSearch
2015-9-29  Malicious URLS
2015-5-19  Dialers
2015-1-5  Email Threats
2013-7-20  Date Manager
2013-4-10  BeeBus
2012-12-18  JT.Moonwalk
2012-12-18  Sadbiz
 

Site EULA | Site Map | Contact Us | About Us | Site and Spyware FAQ | Advertise | RSS Feeds  | Link To Us | SpywareGuide Japan Japanese

© Copyright 2007, FaceTime Communications, Inc. All rights reserved.