WAYS OF INFECTION
Typical AOL parasites are able to propagate by themselves and infect the system without user knowledge. Others must be installed as any other software with or without user consent. There are three major ways unsolicited AOL parasites can get into the system.
1. Lots of AOL parasites infect a computer by exploiting certain software vulnerabilities. They work similarly to worms and automatically spread without user knowledge. The user cannot notice anything suspicious, as such threats do not display any setup wizards, dialogs or warnings.
2. Some AOL parasites rely on user’s carelessness and credulity. They trick an instant messenger user by sending him a message with embedded links leading to insecure web sites or attached files containing malicious code. Usually a threat gets silently installed once a user clicks on such links or opens such files.
3. AOL parasites often are installed by other security and privacy risks such as viruses, trojans, backdoors or even spyware. They get into the system without user knowledge and consent and violate privacy of every user of a particular application. AOL parasites affect mostly computers running Microsoft Windows operating system and specific AOL or ICQ software.
WHAT AN AOL PARASITE DOES?
- Steals various passwords, login names, UINs (Universal Internet Number used in ICQ network), identity details and other sensitive user information.
- Infects or crashes remote computers running vulnerable software by exploiting unfixed security vulnerabilities, sending excessive amount of messages, performing DoS (Denial of Service) or similar network attacks.
- Captures online conversations by logging all user keystrokes typed within AOL Instant Messenger or ICQ program or using other similar techniques.
- Sends messages with attached infected files or links to malicious web sites to all the users from the contact list. Clicking on a link or opening a file usually infects a computer with even more dangerous parasites.
- Retrieves information about installed AOL or ICQ software, finds out computer’s IP address and other network and system information.
- Sends all gathered data to a predefined e-mail address, uploads it to a predetermined FTP server or transfers it through a background Internet connection to a remote host.
- Kills active AIM or ICQ session without asking for user permission.
- Propagates through AIM, ICQ or other chat networks.
- Provides no uninstall feature, hides processes, files and other objects in order to complicate its removal as much as possible.
EXAMPLES OF AOL PARASITES
There are lots of different AOL parasites. The following examples illustrate their typical behavior and payload.
Omerstroke is an AOL parasite that monitors user activity in AIM messenger and records account passwords. It also can capture any user message. Omerstroke sends gathered data to the attacker by e-mail. Once executed, the parasite displays a fake error message and quietly installs itself to the system. Omerstroke automatically runs on every Windows startup and hides from the user.
ICQ Zap sends extremely large amount of messages to a designated ICQ user. Such activity not only severely decreases Internet connection speed and overall performance of an attacked computer, but can also disconnect it from the Internet and crash the entire system.
ISpyU parasite affects ICQ users. It acts as a proxy server, which allows to capture all the chat messages being sent from a computer where ISpyU is installed. The parasite doesn’t harm the system, but poses significant threat for user privacy.
CONSEQUENCES OF INFECTION
Most AOL parasites pose serious threat to user privacy. Attackers analyse conversations captured with the help of these pests in order to find out with whom a user contacts, about what he talks, where he lives, what it does for life, what are his current plans, etc. Malicious persons can get exact identity details, bank account information, even credit card numbers and other sensitive data that unaware users disclose in their personal talks. Furthermore, hackers and potential criminals can use recorded AIM or ICQ login names and passwords to disable particular accounts or use them for unclear purposes. For example, to trick user’s spouse, friends, relatives, colleagues or kids into disclosing critical personal information.
Some AOL parasites cause multiple technical problems. They severely degrade Internet connection speed or make it totally unusable, exploit certain software vulnerabilities to install a way more dangerous parasites, even crash a computer by performing Denial of Service or similar network attacks.
HOW TO REMOVE AN AOL PARASITE?
Most AOL parasites work in the same manner as the computer viruses and therefore can be found and removed with the help of effective antivirus products like Symantec Norton AntiVirus, Kaspersky Anti-Virus, McAfee VirusScan, eTrust EZ Antivirus, Panda Titanium Antivirus, AVG Anti-Virus. Some advanced spyware removers, which are able to scan the system in a similar way antivirus software does and have extensive parasite signature databases can also detect and remove AOL parasites and related components. Powerful anti-spyware solutions such as
Spyware Doctor,
Microsoft AntiSpyware Beta,
Spybot - Search & Destroy,
Ad-Aware SE,
SpyHunter,
eTrust PestPatrol are well-known for perfect AOL parasite detection and removal capabilities.
In some cases even an antivirus or spyware remover can fail to get rid of a particular threat. That is why there are Internet resources such as 2-Spyware.com, which provide manual malware removal instructions. These instructions allow the user to manually delete all the files, directories, registry entries and other objects that belong to a parasite. However, manual removal requires fair system knowledge and therefore can be a quite difficult and tedious task for novices.