Home
Up

If you are a user of the popular AOL Instant Messenger program you may be bombarded with messages seemingly from friends that link to a humorous Osama bin Laden game. Beware of following this link and installing a trojan horse that broadcasts advertisements from the infected computer to all members listed on your AIM buddy list.

The software, called Buddylinks, may not technically be a virus because users must accept its terms of service before it's installed. The small-print legal disclaimer states what's being installed, though users tend to click through such legalese without reading it. And that's one of the keys to its success. The program also uses social engineering to spread, extending a personal invitation that appears to come from a friend.

"In addition to being a particularly slimy form of adware, is also a violation of the AIM terms of service," according to America Online spokesman Andrew Weinstein. "We are actively investigating what legal options we have to prevent this company from doing this."

Anti-virus expert Ken Dunham at iDefense called Buddylinks a worm, due to its self-propagating properties, and said it was "gaining ground in the wild and may prove to be a serious pest over the next few weeks."

On Wednesday, Buddylinks' Web site contained a message denying the program is a virus. The home page also makes no mention that the program would in the future send out additional advertisements using the same method.

"Our games interact with instant messengers by promoting the game among the user's network of buddies," it reads. "Please understand, our flash games are in no way a virus. We simply combine peer-to-peer, social networking, and instant messaging into one spectacular technology."

A source familiar with the software said Buddylinks actually originated from a company called Clickspring, which antivirus companies have identified as a distributor of adware and spyware.

One Clickspring offering, PurityScan, is marketed as a program that scans a computer for unwanted porn but also installs ad-delivery software.