Breaking News

CORSAIR Launches ThermalProtect PCIe 5.1 600W 12V-2x6 Cable to Help Protect GPUs from Overheating Logitech announces G512 X Gaming Keyboard ASUS Announces TUF Gaming Platinum Power Supply Series TerraMaster announces D1 SSD Rugged Enclosure COLORFUL Introduces New BATTLE-AX B860M and B760M Motherboards with Wi-Fi 7 and Next-Gen CPU Support

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

New Skype Virus Confirmed

New Skype Virus Confirmed

Enterprise & IT Sep 11,2007 0

Symantec and F-Secure have bot confirm the existance of a new worm that is affecting users of Skype for Windows. The worm is called "w32/Ramex.A". Users whose computers are infected with this virus will send a chat message to other Skype users asking them to click on a web link that can infect the computer of the person who receives the message.

The worm is also known as "WORM_SKIPI.A [Trend]," and "W32/Pykse.worm.b" [McAfee].

After being run the worm displays an image, usually "Soap Bubbles". This image is a part of the Windows OS (wallpaper), according to F-Secure. The worm then installs itself to the system and creates several startup keys for itself in the Registry. When active, the worm sends messages to all Skype Contacts of the infected computer's user.

Messages usually contain a short text and a URL pointing to the worm's file. The worm also modifies the Windows HOSTS file in order to block access to anti-virus vendor sites. As a part of the payload, the worm terminates processes belonging to anti-virus software. The worm also copies itself to all available removable drives with the name of "game.exe".

There are two ways to get rid of the worm: the normal way and the techhead way. Most users should not attempt to edit their computer’s registry manually. For most people, downloading and/or updating their anti-virus software, and scanning their computer to detect and remove the worm, is the way to go.

Expert users — and only expert users — who know what they’re doing can also remove the worm manually.

- Restart the PC in safe mode
- Run regedit
- Go to HKLM/software/microsoft/windows/currentversion/runonce find entry with mshtmldat32.exe. Delete this entry.
- Go to Windows\System32 directory and delete following files: wndrivs32.exe, mshtmldat32.exe, winlgcvers.exe, sdrivew32.exe
- Go to windows/system32/drivers/etc
- Find file hosts
- Open it with notepad, ctrl+a and delete all entries (this will resume your antivirus updates), save, close.
- Restart the PC.

Tags: SkypeVirus
Previous Post
AMD Releases ATI Catalyst 7.9 Display Drivers
Next Post
SanDisk Announces the New Sansa View

Related Posts

  • Skype's 'Meet Now' Calls Don't Need a Sign-up

  • EU Countries Disagree on Privacy Rules for WhatsApp, Skype

  • Skype's Screen Sharing Goes Mobile

  • Samsung Laptop Full of Notorious Malware Is On Sale For $1.2M

  • New Skype for Web Released But Not For Safari, Firefox or Opera Browsers

  • Skype Introduces Background Blur Feature

  • Apple Removes Skype and Other Apps in China

  • Cortana is Coming to Your Skype Chat Window

Latest News

CORSAIR Launches ThermalProtect PCIe 5.1 600W 12V-2x6 Cable to Help Protect GPUs from Overheating
Enterprise & IT

CORSAIR Launches ThermalProtect PCIe 5.1 600W 12V-2x6 Cable to Help Protect GPUs from Overheating

Logitech announces G512 X Gaming Keyboard
Gaming

Logitech announces G512 X Gaming Keyboard

ASUS Announces TUF Gaming Platinum Power Supply Series
PC components

ASUS Announces TUF Gaming Platinum Power Supply Series

TerraMaster announces D1 SSD Rugged Enclosure
Enterprise & IT

TerraMaster announces D1 SSD Rugged Enclosure

COLORFUL Introduces New BATTLE-AX B860M and B760M Motherboards with Wi-Fi 7 and Next-Gen CPU Support
PC components

COLORFUL Introduces New BATTLE-AX B860M and B760M Motherboards with Wi-Fi 7 and Next-Gen CPU Support

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Arctic Liquid Freezer III 360 Pro Argb

Arctic Liquid Freezer III 360 Pro Argb

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

JSAUX 65Wh Rog Ally Battery

JSAUX 65Wh Rog Ally Battery

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed