I would check the port being used for the IM traffic. If all else fails capture the traffic with wireshark and then block that port. However, IM traffic can be sent over port 80 - which means it might be better for everyone to just remove/block the application on the OS level than to block port 80 on the network.