Akronix, a company that provides IM security and management tools, reports that Q3 2005 attacks on IM networks averaged more than one per day.

The report mentions that IM borne viruses were "often mutations of other varients, however in September, we had seven new viruses." The report did not mention which IM networks were under attack, such as AIM, Yahoo!, or MSN. The report suggests that organizations examine the use of IM on their networks, and prepare to defend their systems from attacks.

According to Akonix, August's worm was the first to ask the client software the local language settings, and sent a text message based on the language settings. Again, it was not reported on which clients were affected by this attack.

It is not known about how many of the millions of IM users are aware that most of their communications are not encrypted when using IM, and that sending of files through them, along with other automated features could introduce attacks onto a computer system.

Dani AI

Generated

A short, practical add-on to the thread: IM-delivered malware often spreads by social engineering (a buddy sends a file or link), then uses persistence and peer-to-peer hooks to reinfect contacts. For someone who downloaded a suspicious IM attachment and now has stability or strange-network activity (as described by ), treat it as an incident: isolate the machine (unplug Ethernet / turn off Wi‑Fi), preserve timestamps/screenshots, and do not reuse that PC to log into banking or email until it’s clean. For formal containment and evidence-preservation steps see the NIST incident‑handling guidance. NIST SP 800‑61. (csrc.nist.gov)

Immediate, safe triage for a home PC (stepwise):

  1. Isolate the host and back up user documents to an external drive (scan that backup later from a clean machine).
  2. Boot to Safe Mode and run up‑to‑date scanners; if the infection resists, run an offline/bootable scanner (for Windows, Microsoft Defender Offline) or vendor rescue media.
  3. Use on‑demand scanners (Microsoft Safety Scanner / MSRT, Malwarebytes/AdwCleaner) from a clean machine to scan/clean.
  4. Find persistence (startup entries, Scheduled Tasks, Services, Hosts) with a tool like Autoruns and disable suspicious entries before rebooting.
  5. If rootkit behavior or repeated reinfection appears, plan a full image wipe and reinstall. See Microsoft Defender Offline and MSRT for offline/removal tools and Autoruns for finding startup persistence. (learn.microsoft.com)

For networks and admins: treat IM like email — apply gateway/proxy scanning or block consumer IM clients, disallow direct transfer of executables, enable logging/archiving and endpoint detection, and add IM to incident response playbooks and user training. Vendor and industry writeups on IM hygiene explain gateway scanning and controls for enterprises. ComputerWeekly overview of IM risks. (computerweekly.com)

Quick checklist (copy/keep):

  • Isolate the PC (network off).
  • Back up user files (scan from a clean system).
  • Run offline bootable scan (Microsoft Defender Offline or rescue media). (learn.microsoft.com)
  • Use Autoruns / Task Scheduler to remove persistence. (learn.microsoft.com)
  • From a different, clean device change passwords and enable MFA.
  • If unsure or infection persists, image‑wipe and reinstall; follow your IR plan. (csrc.nist.gov)

Note: ’s advice to avoid downloading unknown add‑ons is sound — prevention plus a simple IR checklist makes these incidents far easier to handle.

Recommended Answers

All 3 Replies

I just yahoo messenger,,, and i downloaded the blue funbiddies,,and have had computer trouble ever since!! I suspected it was a virus that was associated with the download,, now i'm sure it was! I uninstalled all of my yahoo,,and now just use the mail,, but my computer still is acting up,,better,,but still acting up. Since i'm 'computer challenged',,i'm just going to have to deal with it.

i want to know where you can create a good simple free aimbot, or how do you download Net :: AIM? is that just aim or is it sumthing special? thanks!

This isn't the best place to ask questions like this, but:
sixty_9cents: Don't download anything like that, it's just asking for a virus.
eltommyo: Use IRC and PircBot. :)

On the original article, this is just stupid. If everyone would learn that there are better ways to transfer things besides messages than instant messengers, we wouldn't have problems like this. Why do we need a feature with a just-as-easy-but-more-secure alternative? When was the last time you sent someone a file through AIM instead of email? The same goes for all the Outlook security holes - just access your mail through the web like it should be accessed. Problem solved.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.