SpywareGuide powered by Actiance Security Labs
Search SpywareGuide Database & Site
Home Access the Guide
List of Products List of Companies List of Categories
Tools
X-RayPC
Terms and Definitions
 
Full Name:
W32/AIM.552-B Websearch   Read More
Type: Worm
Also Known as: W32/Opanki-K (SOPHOS) W32/AIM.552-B Lockx
SG Index: 8 [Explain]
Removal tools: List of products that detect/remove/protect against W32/AIM.552-B:
  • IM, P2P control, malware prevention and web filtering in single appliance: Unified Security Gateway
  • Category Description: Virus-like program that spreads automatically to other computers by sending itself out by email or by any other means. A program that propagates itself by attacking other machines and copying itself to the affected machine.

    Worms have self-replicating code that travels from machine to machine by various means. A worms first objective is merely propagation. Worms can be destructive depending on what payload they have been given. Worms may replace files, but do not insert themselves into files.
    Comment: Instant messaging worm that attempts to spread by sending a message containing a link to the worm to all users on the contact list. Allows remote control of computer by a backdoor via IRC channels.

    This particular variant starts with an AOL Instant Messenger (AIM) user being asked to open a link, apparently at the request of an AOL contact. Clicking on this link initiates the infection sequence, which may or may not start with the dropping of a number of adware files, and the rootkit software itself, lockx.exe.

    Once on the computer, the malware attempts to shut down active antivirus software and then installs software that allows the computer to be remotely controlled by IRC, and open a backdoor for future attack. It also contains an SMTP engine which can be used to collect e-mail addresses.

    Of significant note is this has been classified as being the first rootkit spread via IM because of the way it attempts to hide traces of its existence. The rootkit file's use of IRC is also considered especially dangerous because it allows attackers to execute remote commands.
       
    Properties:
  •  Adds other software
  •  Allows remote connect
  •  Allows remote control
  •  Autostarts/Stays Resident
  •  Opens ports
  •  Stealth Tactics
  • Click here to leave feedback for this product

    Recent Modifications
    2012-1-30  HostSeeker Toolbar
    2012-1-13  2000Cracks
    2012-1-13  7AdPower Dialer
    2012-1-13  Absolu-trans
    2012-1-13  AccessPlugin
    2012-1-13  AcidBattery
    2012-1-13  Acidoor
    2012-1-13  Active-X Dialer
    2012-1-13  Adcheat
    2012-1-13  Adh1_sexarea
     
    Company  | Site and Spyware FAQ
    © Copyright 2003-2011, Actiance, Inc. All rights reserved.   Privacy Policy