Friday, December 19, 2008

BEWARE GTALK USERS

Hello friends Have you received some messeges on gtalk or yahoo messengers as follows

Happiness is not a destination. It is a method of life 
or
The wisest mind has something yet to learn
or
View my private cam via secured connection 
or
If you want truly to understand something, try to change it http://rnd009.googlepages.com/google.html

Don't click on the links.This may effect your computer with worms.The name of the worm is Worm.IM.Sohanad.

Worm.IM.Sohanad spreads via Gtalk or Yahoo Messenger and infects Windows. It sends a message to all Yahoo Messenger or gtalk contacts of an infected user. The message(some are mentioned above) contains a link enticing users to download the worm. The worm also disable certain Windows functionalities abd hijacks Internet Explorer homepage. It also downloads other malware and it will also attempt to propagate via the means of creating copies of itself onto removable devices such as USB flash and hard drives.

File System Modifications:
  1. %Windir%\gphone.exe  %System%\gphone.exe
  2. %System%\autorun.ini 
  3. %Windir%\Tasks\At1.job
Generally windir is a system variable whose value is c:\windows\system(in case of windows 95,98) or c:\winnt\system32(windows NT) or c:\windows\system32(windows xp).

Memory Modifications:

process name process file name
   gphone.exe %System%\gphone.exe
   gphone.exe   %Windir%\gphone.exe

Hope You will easily avoid the worm.

No comments:

Post a Comment