Microsoft Windows Vista Community Forums - Vistaheads
Recommended Download - Clean, repair and optimize your system



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Driver Scanner 2009 - Free Scan Now

Another Skype Worm

Security News




Recommended Fix - Fix Vista Errors and Optimize Performance

Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Driver Scanner 2009 - Free Scan Now
Reply
  #1 (permalink)  
Old 04-16-2007
Paul's Avatar
Moderator
 

Join Date: Feb 2007
Location: wicklow mts
Posts: 9,789
Paul will become famous soon enough
Thanks: 0
Thanked 4 Times in 4 Posts
Another Skype Worm
Yup! There is another Skype worm on the loose and our detection for it is IM-Worm:W32/Pykse.A. It spreads by sending a message with a malware link to all online friends in Skype's contact list using the Skype API.

The message is randomly chosen from the following list:

Before sending the message, it will set the infected Skype user's status to DND (Do Not Disturb). As a side effect, it will not actively notify the user of calls or messages as shown in the warning message below:

Once the link is clicked, it will redirect and download the malware file:

Once you have downloaded and executed the file from the link, it will show you a picture of a lightly dressed woman, to avoid suspicion:

So what's the motive behind this worm?
It seems that it is promoting the following websites:

http://aras.lookingat.us/index.htm
http://asilas.my-php.net/index.html
http://bobodada.3-hosting.net/index.html
http://bobos45.bebto.com/index.html
http://gogo442.hatesit.com/index.html
http://jackdaniels.110mb.com/index.html
http://timboss.1majorhost.com/index.html
http://zozole.php0h.com/index.html

These websites all look the same. Here's a sample screenshot:

The following site is also visited:
http://aras.allfreehost.net/cal[REMOVED]nt.php
This is most probably a counter to find out how many users are infected. This could also be a way for the malware writer to quantify his profit. Who knows, malware nowadays are mostly driven and motivated financially.

Signing off Skype,
Francis On 16/04/07 At 03:16 AM


More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Another Skype Worm Paul Security News 0 04-16-2007 06:12
skype =?Utf-8?B?bHluZGE=?= microsoft.public.windows.vista.general 1 03-08-2007 22:14
3/1: SunOS/Wanuk.worm Detects Solaris Telnet Worm Paul Security News 0 03-01-2007 22:49
Warezov worm fiends target Skype Paul Security News 0 03-01-2007 02:28
Warezov worm fiends target Skype Paul Security News 0 02-28-2007 19:32




All times are GMT +1. The time now is 04:57.




Driver Scanner - Free Scan Now

Vistaheads.com is part of the Heads Network. See also XPHeads.com and Win7Heads.com.


Funny Commercials to make you laugh :-)

Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119