About Me

Pradeep Govindaraju

Pradeep Govindaraju

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

W32/Pykse.worm: Skype worm strikes with Bubbles!!

Tuesday, September 11, 2007 at 5:52am by Pradeep Govindaraju
Pradeep Govindaraju

Last year, McAfee Avert Labs had predicted an increase in malware targeting VOIP particularly Skype, given the APIs of Skype are well documented in their SDK. With Skype becoming increasingly popular, it is an attractive target for malware authors.

The W32/Stration family of worms which started out as a mass mailing family, later used IM with reasonable success to spread. And Skype was the first IM protocol to be targeted by this worm, followed by MSN and ICQ.

As predicted earlier, McAfee Avert Labs has recently received multiple submissions of the W32/Pykse.worm.b spreading via Skype. This worm uses clever social engineering to spread via Skype chat messages.

Upon execution on the victim’s machine, it launches the “soap bubbles.bmp” from the default windows directory to deceive user to believe that it is an image file.

Bubbles

In the meantime, the worm changes the status of Skype to “Do Not Disturb” and starts sending messages to everyone in the Skype’s contacts list, without the user’s knowledge. One of the messages sent, will be a URL pointing to a copy of the worm. The following screenshot shows chat the messages used as bait by this worm.

Chat messages sent by the worm

This worm can also prevent security related tools and programs from being launched and modifies the hosts file to prevent access to Antivirus websites.

Following image shows the APIs used by the worm to spread using Skype.

Skype APIs used by the worm

More information on this threat can be viewed at our virus information library.
http://vil.nai.com/vil/content/v_143083.htm

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (2)

  • Vinoo Thomas September 12, 2007 11:03PM

    Hi Janet,

    Just receiving this link via Skype and clicking it will not infect your machine. The sites hosting the worm currently do not use any browser based exploits to perform a silent drive-by install of the malware. You would have to manually download and execute the worm executable in order to get infected.

    Please update McAfee VirusScan to the latest DAT files as they cover known variants of this worm seen in the wild.

  • Janet September 12, 2007 5:40AM

    so how do i remove it? i have mcafee through comcast and that clearly didn’t block it….