Breaking News

ASUS Announces ProArt Router PRT-BE5000 and ProArt Switch PQG-U1080 CORSAIR Expands the Popular FRAME Series Case Lineup DeepCool Launches the LT360 VISION ARGB Noctua and Asetek Announce Flagship AIO Liquid Coolers Toshiba Begins Sampling of 30-34 TB SMR Nearline Hard Disk Drives

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

New Skype Virus Confirmed

New Skype Virus Confirmed

Enterprise & IT Sep 11,2007 0

Symantec and F-Secure have bot confirm the existance of a new worm that is affecting users of Skype for Windows. The worm is called "w32/Ramex.A". Users whose computers are infected with this virus will send a chat message to other Skype users asking them to click on a web link that can infect the computer of the person who receives the message.

The worm is also known as "WORM_SKIPI.A [Trend]," and "W32/Pykse.worm.b" [McAfee].

After being run the worm displays an image, usually "Soap Bubbles". This image is a part of the Windows OS (wallpaper), according to F-Secure. The worm then installs itself to the system and creates several startup keys for itself in the Registry. When active, the worm sends messages to all Skype Contacts of the infected computer's user.

Messages usually contain a short text and a URL pointing to the worm's file. The worm also modifies the Windows HOSTS file in order to block access to anti-virus vendor sites. As a part of the payload, the worm terminates processes belonging to anti-virus software. The worm also copies itself to all available removable drives with the name of "game.exe".

There are two ways to get rid of the worm: the normal way and the techhead way. Most users should not attempt to edit their computer’s registry manually. For most people, downloading and/or updating their anti-virus software, and scanning their computer to detect and remove the worm, is the way to go.

Expert users — and only expert users — who know what they’re doing can also remove the worm manually.

- Restart the PC in safe mode
- Run regedit
- Go to HKLM/software/microsoft/windows/currentversion/runonce find entry with mshtmldat32.exe. Delete this entry.
- Go to Windows\System32 directory and delete following files: wndrivs32.exe, mshtmldat32.exe, winlgcvers.exe, sdrivew32.exe
- Go to windows/system32/drivers/etc
- Find file hosts
- Open it with notepad, ctrl+a and delete all entries (this will resume your antivirus updates), save, close.
- Restart the PC.

Tags: SkypeVirus
Previous Post
AMD Releases ATI Catalyst 7.9 Display Drivers
Next Post
SanDisk Announces the New Sansa View

Related Posts

  • Skype's 'Meet Now' Calls Don't Need a Sign-up

  • EU Countries Disagree on Privacy Rules for WhatsApp, Skype

  • Skype's Screen Sharing Goes Mobile

  • Samsung Laptop Full of Notorious Malware Is On Sale For $1.2M

  • New Skype for Web Released But Not For Safari, Firefox or Opera Browsers

  • Skype Introduces Background Blur Feature

  • Apple Removes Skype and Other Apps in China

  • Cortana is Coming to Your Skype Chat Window

Latest News

ASUS Announces ProArt Router PRT-BE5000 and ProArt Switch PQG-U1080
Enterprise & IT

ASUS Announces ProArt Router PRT-BE5000 and ProArt Switch PQG-U1080

CORSAIR Expands the Popular FRAME Series Case Lineup
Cooling Systems

CORSAIR Expands the Popular FRAME Series Case Lineup

DeepCool Launches the LT360 VISION ARGB
Cooling Systems

DeepCool Launches the LT360 VISION ARGB

Noctua and Asetek Announce Flagship AIO Liquid Coolers
Cooling Systems

Noctua and Asetek Announce Flagship AIO Liquid Coolers

Toshiba Begins Sampling of 30-34 TB SMR Nearline Hard Disk Drives
Enterprise & IT

Toshiba Begins Sampling of 30-34 TB SMR Nearline Hard Disk Drives

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Arctic Liquid Freezer III 360 Pro Argb

Arctic Liquid Freezer III 360 Pro Argb

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed