Slashdot Mirror


Skype Worm Infects Windows PCs

walterbays writes with news of a worm spreading to Windows PCs through Skype's IM. The worm is variously called Ramex.a and Pykspa.d. A poster on a Skype forum explains how to remove it. "After hijacking contacts from an infected machine's Skype software, it sends messages to those people that include a live link. Recipients who blithely click on the URL — which poses as a JPG image but is actually a download to a file with the .scr extension — wind up infected."

22 of 127 comments (clear)

  1. Worm? by Hatta · · Score: 4, Insightful

    Recipients who blithely click on the URL -- which poses as a JPG image but is actually a download to a file with the .scr extension -- wind up infected.

    I'm sure I won't be the first to point out that such an attack vector is not a worm.

    --
    Give me Classic Slashdot or give me death!
    1. Re:Worm? by Anonymous Coward · · Score: 5, Funny

      Given your position of first post, I can't see how you could be anything but the first to point out this.

    2. Re:Worm? by Bill,+Shooter+of+Bul · · Score: 4, Funny

      That is a good point, and I must admit I thought that as well ... at first. Then I started thinking, How long is something really first? Is something first always first? Like the first European to visit the Americas, Columbus. He was first, but only for 400 odd years before we discovered that the vikings were the first. Also, one can never be so certain that time travel will never exist. Therefore, all of our first records in any given field may be only temporary, before some one from the future comes back and does it first.

      I applaud the gp's modesty, and four dimensional thinking. I think we should all be a little more considerate of our resources, both natural and produced, in light of the fact that they may belong to someone else before us, in the future.

      --
      Well.. maybe. Or Maybe not. But Definitely not sort of.
    3. Re:Worm? by Doctor-Optimal · · Score: 4, Funny

      Ooh, a lesson in not changing history from mister "I'm-my-own-grandpa"!

      --
      New punctuation update "~" (no quotes) at the end of a line to indicate sarcasm. ~
  2. F-Secure info by CXI · · Score: 4, Informative
  3. Skype itself is blameless by ZwJGR · · Score: 5, Insightful

    Skype itself is (mostly) blameless, how can they be expected to protect users from this sort of attack (perhaps by pointing out to users that the link/download they're clicking on is a screensaver exe..., but Windows ought to tell you that anyway...)
    Naming it a worm is a minor overstatement as well.
    It propagates by user incompetence, not by a technical flaw...

    These sort of malware executables circulate on email lists (and I daresay, other IM networks) already, so it's no surprise that Skype has "joined the club" of being big enough to attract unwanted attention...

    --
    There is no psychiatrist in the world like a puppy licking your face - Ben Williams
    1. Re:Skype itself is blameless by jimicus · · Score: 4, Insightful

      It propagates by user incompetence, not by a technical flaw...

      If the last 8-10 years have taught the IT industry nothing else, we should at least be well aware by now that basing your security on "user never does anything stupid" is a pretty effective way to ensure that the user's system will be emailing everyone and his dog adverts for Geniun Vigara!!!111 (sic) by the end of the day.

    2. Re:Skype itself is blameless by gowen · · Score: 5, Insightful

      Skype itself is (mostly) blameless
      You what? Their program runs executable content from a URL without a warning or asking for confirmation. That's insanely bad design.
      --
      Athletic Scholarships to universities make as much sense as academic scholarships to sports teams.
  4. Skype's revenge by Nimey · · Score: 3, Funny

    They're getting back at all the people who rebooted last month.

    --
    Hail Eris, full of mischief...

    E pluribus sanguinem
  5. Re:Software diversity is a good thing. by abigor · · Score: 3, Insightful

    You have no idea what you're talking about.

  6. Re:Software diversity is a good thing. by Opportunist · · Score: 4, Insightful

    And how? By not implementing a messenging system the moron user can click and infect himself?

    Where's Skype to blame if someone gets a link sent and clicks it without even trying to see what's behind it?

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  7. FIXED by Anonymous Coward · · Score: 5, Funny

    s/some of the //

  8. Re:Amazing by recoiledsnake · · Score: 3, Informative

    Uh. IE7 on Vista runs in a sandbox(note that this is to mitigate the damage caused by buffer overflows in IE code and not intended to sandbox executable/virus code), and warns you square whenever that boundary is breached(by opening a PDF, EXE or SCR, for example). Additionally, if the EXE requests admin privileges(required to install a rootkit, for example), the infamous UAC dialog appears. And if someone gives admin access when they wanted to view a JPEG, how is it Windows' or Skype's fault? Also, most versions of windows I have used(since 95) ask before opening executable files(even .SCR) So, Windows does not "still" allow un-sandboxed applications to run just clicking links. If users expect a JPEG but get a .scr or exe they have plenty of time/opportunity to click NO. This is not Windows or Skype's fault. It's just clueless users getting owned.

    --
    This space for rent.
  9. Re:"blithely" by Anonymous Coward · · Score: 3, Funny

    Considering the definition and my general knowledge from doing tech support, I'd say just about all of them:

    blithely:
    1- of a happy lighthearted character or disposition
    2- lacking due thought or consideration

  10. Microsoft's fault? by sconeu · · Score: 3, Informative

    With the default behavior of hiding the extension, XP leaves non-technically proficient users vulnerable to this.

    --
    General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    1. Re:Microsoft's fault? by recoiledsnake · · Score: 4, Insightful
      I fail to see how that behavior makes a difference here. The user clicks on a link that ends in .JPG, and the browser asks him to run or save an SCR file. No hiding the extension is involved here. If the user runs it, BAM. If he saves it, THEN he or someone else would not be able to see the extension and would run it(Though I think XP SP2 pops up a warning about it being a file from the internet zone, not sure if the full filename shows up in the warning though).

      Hiding the extension is a very most annoying thing though, it's the first setting that I change on a new install of Windows.

      --
      This space for rent.
    2. Re:Microsoft's fault? by cbhacking · · Score: 3, Informative

      I think XP SP2 pops up a warning about it being a file from the internet zone, not sure if the full filename shows up in the warning though It doesn't matter, since jpegs (non-executable data files in general) don't present that warning (The text of the warning is something along the line of "this type of file can harm your computer". Not to mention they would presumably notice the file type while downloading and cancel the download / delete the file. Of course, the fact that anybody GETS these warnings (I haven't gotten one in Skype, but I've seen a couple that were near-identical over AIM) means that there are people out there who are actually stupid enough to ignore the warning...

      Hiding the extension is a very most annoying thing though, it's the first setting that I change on a new install of Windows. Agreed, although I actually change roughly half the options in Folder Settings. It's gotten better over time; 2000 you had to change almost all of them, XP only about 80%, Vista is down to nearly 50%. IE's default settings have gotten better too, especially with 7.
      --
      There's no place I could be, since I've found Serenity...
  11. Re:Lovely by recoiledsnake · · Score: 4, Informative

    It does not "inject code" into Explorer any more than Notepad injects code into Explorer to run itself. An "infected user" is probably not the right person to listen to in such technical matters. FSecure has complete details on it if you're really interested here

    --
    This space for rent.
  12. Re:Lovely by Peaker · · Score: 3, Informative

    It does not "inject code" into Explorer any more than Notepad injects code into Explorer to run itself. An "infected user" is probably not the right person to listen to in such technical matters. FSecure has complete details on it if you're really interested here

    Heh, I am Eyal. I admit I was "infected". Basically I clicked the "scr" link because I foolishly trusted the source of the message to be who it was, did not read the contents before clicking, I don't really give much of a damn about this Windows box, and I forgot that the "scr" extension was executable, and not just an image file (which is typically a less likely attack vector).

    I assumed that since the Explorer.exe was unmodified, but explorer.exe is respawning the virus/worm's executable, that it modified Explorer's behavior in some way, perhaps by code injection. It was just speculation, ofcourse and obviously there are simpler ways to get explorer.exe to respawn your process, but it really is an unimportant detail.
  13. Yet Again... by RAMMS+EIN · · Score: 3, Funny

    Yet again, us Linux users are left out. The program works only on Windows/x86. And here I am, on my glorious Linux/ppc box, just having painfully gotten Skype to work...and they introduce a new feature that I can't access...boohooo!

    (I kid. I hate Skype passionately (for getting everybody on a proprietary solution when open protocols exist) and would never go through any amount of trouble to get it installed on my computer.)

    --
    Please correct me if I got my facts wrong.
  14. Re:The malware terminates a list of 534 processes. by myowntrueself · · Score: 3, Funny

    Seems like such a person could make money honestly.

    Anyone who can make $money honestly could make N * $money dishonestly.

    How do you think corporatism works? :-P

    --
    In the free world the media isn't government run; the government is media run.
  15. 110% of them by OrangeTide · · Score: 3, Funny

    Most skype users don't know what blithely means. And are unaware of any fundamental difference between a spell-checker and a dictionary.

    --
    “Common sense is not so common.” — Voltaire