Worm wears iTunes guise
Runs malware not music
Posted in Anti-Virus, 21st July 2005 10:59 GMT
Webcast: Building Applications for the 21st Century
The latest incarnation of the Opanki worm, which spreads itself using AOL Instant Messenger, has begun targeting iTunes users.
The worm appears as a message headed 'this picture never gets old' and carries as a payload a link to a file called itunes.exe. Anyone who clicks on the link to download the Apple app receives the worm, which modifies Windows to ensure it runs whenever the host machine is restarted, and downloads a set of four adware programs.
According to anti-virus specialist Trend Micro, the worm also opens a random TCP port, and connects to an IRC server where it listens out for commands which, if received, it will run on the infected machine.
Trend rates the threat as low, noting that it has detected relatively few infected computers out there. The worm targets Windows PCs running all versions of the operating system from 95 onwards. ®
Related stories
'Alien greeting' harbours Windows malware
Malware maelstrom menaces UK
Industry coalition takes stab at defining spyware
Adware makers exploit BitTorrent
Hackers plot to create massive botnet
VXers creating 150 zombie programs a week

The Register Guide to Extended Validation
LDAP Injection [3-2APZ1KL]
Blind SQL Injection [3-2APYM5E]
Preventing Google Hacking [3-2APYMGU]
Building Web Application Security into Your Development Process [3-2APYMBV]

Inmate hacked prison network, broke into employee database
Miscreants hijacking machines via (freshly patched) Adobe flaw
Martial law planned for Craigslist's red-light district
Cocaine addicted IT manager hacks ex-employer's mail servers