A worm targeting Windows operating systems hides in a file named itunes.exe, and will try distributing itself over AIM. Antivirus maker Trend Micro says the Opanki worm’s name may trick people into thinking it is a legitimate file associated with Apple’s iTunes Music Store:
This worm arrives as the file, ITUNES.EXE. Its file name may appear familiar to users as it is similar to the name of a popular media player from Apple Computer. Thus, users may be tricked into thinking that this worm is associated with a legitimate product.
It spreads via AOL Instant Messenger (AIM). It sends the following message to all online contacts of an affected user:
“this picture never gets old”
This worm has backdoor capabilities. It opens a random TCP port and connects to the Internet Relay Chat (IRC) server xyz.legi0n.net. Once connected, it joins the IRC channel #fate, where it listens for commands from a remote malicious user. It then executes these commands locally on affected machines.
It also downloads and executes other applications, mainly adware programs, into affected machines.
Full article here.
MacDailyNews Take: Trend Micro advises that Windows users should make sure that their their antivirus programs are up to date, to help protect against this worm and many other virus problems. Of course, you could just get a Mac where the real iTunes music jukebox runs much better and Windows worms, viruses, adware, spyware, and other malware won’t run at all.
Related MacDailyNews articles:
Microsoft Windows Sober.P worm shows ‘epidemic’ spread; Macintosh unaffected – May 03, 2005
Apple touts Mac OS X security advantages over Windows – April 13, 2005
97,467 Microsoft Windows viruses vs. zero for Apple Mac’s OS X – April 05, 2005