The Enterprise Security Supersite
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Network Security Viruses & Malware Spam & Hackers Security Products More Topics...
Network Security
Average Rating:
Rate this article:  
Skype Users Slammed by New Virus Skype Users Slammed by New Virus
By Richard Koman
September 11, 2007 11:01AM

Bookmark and Share
According to F-Secure, the new worm targeting Skype users creates several startup keys for itself in the Windows Registry and even modifies the Windows hosts file to block access to antivirus vendor sites. The new Skype worm also terminates processes belonging to antivirus software and copies itself to removable drives so it can replicate.
 


"Hey, where I put ur photo ;-) now u populr. oops sorry please dont look there. look what crazy photo Tiffany sent me, looks cool." Skype users were seeing variations of that innocent-seeming text message Monday and Tuesday, as a virus targeted the peer-to-peer telephony network Relevant Products/Services.

Deemed Skipi.A by F-Secure and Pykspa.D by Symantec, the virus is a worm that disables antivirus software, installs password-sniffing software, and spreads by sending chat messages to other Skype users, inviting them to click on the links.

Antivirus companies F-Secure, Kaspersky Lab, and Symantec already have updated their software to catch and remove the worm, according to Skyp's Villu Arak. The virus only affects Windows Relevant Products/Services computers.

Antivirus Software Updated

According to Arak, when users click on the link to a supposed image, a Windows dialog box pops up. If the user runs or saves the file, the machine will be infected with the worm. The worm uses Skype's application programming interface (API) to access the PC, Arak said.

According to F-Secure, the worm creates several startup keys for itself in the Windows Registry and modifies the Windows hosts file to block access to antivirus vendor sites. It also "terminates processes belonging to antivirus software," F-Secure said, and copies itself to removable hard drives.

Most users should update their antivirus software and scan Relevant Products/Services for the worm, Arak said. Expert users can follow directions on the Skype blog or at the Symantec and F-Secure pages linked from the blog to manually delete the virus.

Attack Not Over

As of Tuesday morning, the worm attack was "not over," Phil Wolff, editor of the independent Web site Skype Journal, said via Skype chat. "I can't tell the scope but I'm still getting a handful of outputs in my inbox this morning."

This appears to be the first virus attack against Skype, Wolff said. "Contrast this to the many viruses and worms you've seen over the years with other carriers," he said. "In my mind, this is just confirmation that the Skype community has become large enough to warrant virus writers' time."

Skype would certainly be happy to sidestep this confirmation of its success, especially because a days-long outage is still fresh in users' minds. Will repeated virus attacks at the system Relevant Products/Services remind users one too many times that Skype is not the phone company?

"I doubt Skype ever had that reputation," Wolff said. "Skype is Skype, with a fairly unique positioning in the marketplace. It's a more flexible communication tool than the phone, [and it] works over many kinds of Internet connections, but it is fundamentally a product of the desktop and the Internet, with all the usual problems that go with it."

The outage has not had a "direct impact on users or adoption," Wolff said. "I'm sure Skype is putting a few measures in place to identify growing outages faster, predict them through modeling and simulation, and deploy systems to speed recovery from interruptions."
 

Tell Us What You Think
Your Comment:



Advertisement


 Network Security
1.   China Cyberattacks: Pervasive Threat
2.   Cybersecurity Appears Hot for 2010
3.   EPIC Objects To Google-NSA Ties
4.   Torrent Traps Used To Harvest Logins
5.   For Good Passwords, Think Sentence


advertisement
EPIC Objects To Google-NSA TiesEPIC Objects To Google-NSA Ties
Cyberattack meant to rattle Google?
Average Rating:
Torrent Traps Used To Harvest LoginsTorrent Traps Used To Harvest Logins
Web sites sold with backdoor access.
Average Rating:
Social Networks: A Hacker's DelightSocial Networks: A Hacker's Delight
Workers urged to be 'trained skeptics.'
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Mobile Enterprise Spotlight
Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.
 
'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.
 
Review: Palm's Pre Plus Is Losing Pace
There's a lot to like about the Pre Plus and its underlying webOS. The 3-D graphics capability is great. Regrettably, the Pre Plus doesn't do justice to the potential and impressive capabilities of Palm's webOS.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Spam & Hackers | Security Products | Mobile Security | Windows Security | Data Security
EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.