Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 9th, 2005, 02:45 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,216
Default Security Firm Warns of IM Worm

Quote:
The latest IM spyware worm, is named Chode-D, is moving rapidly over leading public IM networks, the security center said. The worm has been classified as a "medium risk.

Article
  #2  
Old August 12th, 2005, 06:34 AM
cleverboy123 cleverboy123 is offline
Infrequent Poster
 
Join Date: Aug 2005
Location: London
Posts: 13
Default Re: Security Firm Warns of IM Worm

Interesting- You should never open files in IM even if you know what it is !

Better to b safe than sorry !
__________________
CLEVERBOY123
  #3  
Old August 12th, 2005, 02:09 PM
Randy_Bell's Avatar
Randy_Bell Randy_Bell is offline
Updates Team
 
Join Date: May 2002
Location: Santa Clara, CA
Posts: 3,053
Exclamation Trend Micro Virus Alert: WORM_CHOD.D

WORM_CHOD.D is a non-destructive, memory-resident worm that propagates via email and MSN Messenger. It spreads via email by sending copies of itself as an attachment to email messages,by gathering addresses from the Windows registry of affected machines. It spreads via MSN Messenger by sending a URL to all available contacts in the messaging application. Once the users click the URL, they are immediately redirected to a Web site, where this worm automatically downloads itself. This worm is currently spreading in-the-wild and infecting computers running Windows ME, NT, 2000, XP and Server 2003.

Upon execution, it creates a randomly generated folder in the Windows system folder and drops files in this created folder. It also modifies a particular registry entry to disable the services used by Trend Micro products.

The worm's backdoor capabilities attempt to open port 37737 to connect to a certain Internet Relay Chat (IRC) server. If it fails to open the port, it attempts to open random TCP ports. It then joins a particular IRC channel, where it waits for malicious commands from a remote malicious user. It also tries to use a password recovery tool to retrieve passwords available on an affected system. It can send the obtained information to the malicious user using its backdoor capabilities.

If you would like to scan your computer for WORM_CHOD.D, or thousands of other worms, viruses, Trojans and malicious code, visit HouseCall, Trend Micro's free, online virus scanner at: http://housecall.trendmicro.com/

WORM_CHOD.D is detected and cleaned by Trend Micro pattern file #2.764.02 and above.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:36 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums