New IM Worm On The Loose

Dubbed Funner, the worm propagates by sending itself to all the contacts listed in the user's copy of MSN Messenger, Microsoft's IM client.

According to Symantec's alert, Funner may also try to contact a domain -- -- to download additional components.

Other than reproducing, Funner's main purpose seems to be to modify Windows' Hosts file on the compromised machine so that attempts to contact any of some 937 sites -- many of them Asian porn sites -- will be redirected to the IP address that matches That Web site, however, was offline as of mid-morning Monday.

Both Symantec and rival McAfee have labeled Funner as a low-level threat for the moment.

