Thursday, December 18, 2014
Search
  
Submit your own News for
inclusion in our Site.
Click here...
Breaking News
ICANN Targeted in Phishing Attack
BlackBerry Classic Makes Official Debut
LG, Samsung, To Dominate The TV Market in 2015
Renesas Develops 16nm FinFET SRAM
Sony Film Debut Canceled After Threats
New Nintendo Devices To Use 'free-form' LCDs
Sony Single-Lens OLED Display Module Turns Any Eyewear Into Smartglasses
Dutch Privacy Watchdog Probes Facebook
Active Discussions
Windows xp
Will there be any trade in scheme for the coming PSP Go?
Hello, Glad to be Aboard!!!
Best optical drive for ripping CD's? My LG 4163B is mediocre.
Hi All!
cdrw trouble
CDR for car Sat Nav
DVD/DL for Optiarc 7191S at 8X
 Home > News > General Computing > New Sky...
Last 7 Days News : SU MO TU WE TH FR SA All News

Tuesday, September 11, 2007
New Skype Virus Confirmed


Symantec and F-Secure have bot confirm the existance of a new worm that is affecting users of Skype for Windows.

The worm is called "w32/Ramex.A". Users whose computers are infected with this virus will send a chat message to other Skype users asking them to click on a web link that can infect the computer of the person who receives the message.

The worm is also known as "WORM_SKIPI.A [Trend]," and "W32/Pykse.worm.b" [McAfee].

After being run the worm displays an image, usually "Soap Bubbles". This image is a part of the Windows OS (wallpaper), according to F-Secure. The worm then installs itself to the system and creates several startup keys for itself in the Registry. When active, the worm sends messages to all Skype Contacts of the infected computer's user.

Messages usually contain a short text and a URL pointing to the worm's file. The worm also modifies the Windows HOSTS file in order to block access to anti-virus vendor sites. As a part of the payload, the worm terminates processes belonging to anti-virus software. The worm also copies itself to all available removable drives with the name of "game.exe".

There are two ways to get rid of the worm: the normal way and the techhead way. Most users should not attempt to edit their computer?s registry manually. For most people, downloading and/or updating their anti-virus software, and scanning their computer to detect and remove the worm, is the way to go.

Expert users ? and only expert users ? who know what they?re doing can also remove the worm manually.

- Restart the PC in safe mode
- Run regedit
- Go to HKLM/software/microsoft/windows/currentversion/runonce find entry with mshtmldat32.exe. Delete this entry.
- Go to Windows\System32 directory and delete following files: wndrivs32.exe, mshtmldat32.exe, winlgcvers.exe, sdrivew32.exe
- Go to windows/system32/drivers/etc
- Find file hosts
- Open it with notepad, ctrl+a and delete all entries (this will resume your antivirus updates), save, close.
- Restart the PC.


Previous
Next
AMD Releases ATI Catalyst 7.9 Display Drivers        All News        SanDisk Announces the New Sansa View
Microsoft and Novell Open Interoperability Lab     General Computing News      Microsoft aims at VMware's virtualization Lead

Get RSS feed Easy Print E-Mail this Message

Related News
Skype Gets Auto-translation Feature
Researchers Identify New iOS Vulnerability
Skype Translator Early Preview Online
Skype Qik Keeps You Engaged Between Calls
Latest Skype For Windows Phone Brings Cortana Integration
Microsoft Demos Real-time Translation For Skype
Group video Calls on Skype Now Free on Windows desktop, Xbox One and Macs
Skype for Outlook.com Now Globally Available
European Court Rejects Cisco's Challenge Of Microsoft-Skype Deal
Microsoft Fights Back Against Skype Censorship in China
Dropbox, WordPress Used To Spread Malware
Skype for Windows 8 Gets Enhanced HD Video Support

Most Popular News
 
Home | News | All News | Reviews | Articles | Guides | Download | Expert Area | Forum | Site Info
Site best viewed at 1024x768+ - CDRINFO.COM 1998-2014 - All rights reserved -
Privacy policy - Contact Us .