Skype Logo
Buy Skype Credit · Help ·
  • Download
  • Use Skype
  • Business
  • Shop
  • Account
Villu Arak

Updated: Malware alert

By My status Villu Arak on November 5, 2007 in Trojans and viruses.

It has come to our attention that some Skype for Windows users have been affected by a piece of malware that masquerades as a chat message aimed at finding a lost girl.

Please do not follow any internet links you may receive in chat messages that resemble the following: "Please help me to find this Girl".

Clicking on the link will lead you to download a worm that is currently best described here.

Currently, this piece of malware -- a new strain of the Stration/Warezov worm -- can be detected by the following antivirus software: AntiVir, ArcaVir, AVG Antivirus, BitDefender, F-Secure, Kaspersky, McAfee, Microsoft, Norman Virus Control, Panda Antivirus, Sophos Antivirus, TrendMicro, VBA32.

Bookmark and Share

View blog reactions

Comments

I received this via chat today:

*** Show messages from: This conversation | Today | This week | Last 30 days | Beginning ***
[12:32:06 AM] Scan Alert ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows NT Workstation
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.alertmonitor.org/?q=updatescan

dan71153 | Tuesday, Nov 6

this is what I just recieved:
[11/20/2007 7:01:42 PM] System Alert ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows NT Workstation
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.alertscan.net/?q=update

ales.vanek | Wednesday, Nov 21

i just got the same thing:
*** Show messages from: This conversation | Today | This week | Last 30 days | Beginning ***
[11:01:39 AM] System Alert ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows NT Workstation
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.systemalert.net/?q=update

any advice on what it is and how to get rid of it?

kudomonster | Wednesday, Dec 5

I got the same thing today:
[10:24:48 PM] System Alert ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows NT Workstation
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.systemalert.net/?q=update

stevendek | Thursday, Dec 6

I got it too.
Check http://share.skype.com/sites/security/2007/11/fake_malware_alert.html for what looks like Skype's official response. (They say it's fake malware)

dphbrit | Thursday, Dec 6

What I received is below(same except from "Update Notice").

This does not seem like it's malware, really, except that it's strong spam (strong urge to get you to visit a site).


[6:16:54 PM] Update Notice ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows NT Workstation
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.updatew.org/?q=scan

(End of malware)

curt.beckmann | Sunday, Jan 6

January 12, 2008
BEWARE!!!!
Today I received a similar message.

The profile of the user: "update.notice.jk19".

WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows NT Workstation
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.updatew.org/?q=scan

malberini | Sunday, Jan 13

I received this too

http://www.updatew.org/?q=scan

today jan 15, 2008

paollo85 | Wednesday, Jan 16

I received the same message, but link to http://www.onlinemon.info/?q=scan.

this stinks.

meskinner001 | Friday, Feb 8

I got a message from a user, the user was Online Monitor (R) online.monitor.ko13 , with a message containing a trojan virus. The message was:

WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows NT Workstation
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.http://www.onlinemon.info/?q=scan

babie_gurl_16 | Sunday, Feb 17

I received the same link to http://www.onlinemon.info/?q=scan.

Be very careful

rrayll1 | Friday, Feb 22

I received this dummy message and link today (2008-02-22). Since I'm working with Macintoshes computer and can't be infected with these malware, I visit the address http://www.onlinemon.info/?q=scan and I found a web page where an animation simulates a scanning process on my 'PC'. The HTML source for this page reveals a lot of javascript.

It takes about 30 seconds for the "scanning process" (and animation) to complete and guess what, the page pretend my 'PC' is infected with some very bad back door and Trojan viruses. :O) Once again, I running a Mac with Os X on it !!
Of course, the site pretend they has a solution to remove these malware from my 'Windows' but you can be sure their wills are exactly the contrary.

If you are on Pc/Windows, DO NOT follow these links and forgot the instructions you received. It is sad to see how these stupid persons are badly using a service like Skype.

fmgeek | Friday, Feb 22

And here:

6:25:50 PM] System Status ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows NT Workstation
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.onlinemon.info/?q=scan

xetheare | Wednesday, Feb 27

Oh yea, what clued me in was that it affects Win98 and XP, two totally different OS's

I have NoScript on my Firefox so I plugged in the address and It says "Scan Alert Making the web hacker safe". Ha! safe for the hackers huh.

xetheare | Wednesday, Feb 27

I have also just gotten the following msg. I didn't do anything it said to do, I was afraid of it definately being something harmful to my computer. I think it is very smart to check anything out like this before downloading.

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows NT Workstation
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.onlinemon.info/?q=scan

dottie.turner | Wednesday, Feb 27

I didn't click it especially after finding these posts.

Received 3/3/08 at:

[3:48:11 PM] CompuAlarm ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows NT Workstation
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.onlinemon.info/?q=scan

bratae | Monday, Mar 3

I got it today, too. Glad this blog was here - and that I checked before responding! Can't Skype do something to stop this??? Seems to be their responsibility to stop it or notify all users about the problem asap. Should we, as Skype users, notify all of our Skype contacts about the issue? Hope Skype can come up with a quick response before they have a whole bunch of angry customers!

tomdaniel1036 | Friday, Mar 7

I just this message today too. Luckily I knew not to click the link and that whoever sending this is full of ****.

luxornv | Thursday, Mar 13

Ah, OK. I was browsing through the UDP logs on my linux box and this stupid message was in there several times. Now I understand, it is intended for some win machines which show the content of the message without control.

It is a Microsoft Messenger Service request (goes to your port 1027) and for some strange reason it appears to you as a system message. So the malware you have is the built-in Messenger Service, most likely you have to disable it to make these messages go away.

I found this on the MS site how to turn it off:
http://www.microsoft.com/windowsxp/using/security/learnmore/stopspam.mspx

pemgasan | Saturday, Mar 15

To all fellow Skype users,

I also received the following message on a chat this morning. I ALMOST downloaded the requested software, but thanks to seeing this message i haven't.
Just a warning for all others that this looks VERY sketchy and DON'T download it!!

[2:08:21 AM] SoftWarning ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows NT Workstation
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.onlinemon.info/?q=scan

barticus1 | Tuesday, Apr 15

I also got the same message with the title "Software Alarm" followed by an R in a circle meaning it is a trademark:

WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows NT Workstation
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.onlinemon.info/?q=scan

I was alerted by the fact that it had a trademark symbol that it was some type of solicitation. That said, just when it came in, my computer started going haywire with my browser saying Norton security was turned off, etc. and I had to do a hard reboot. So I think maybe it puts something nasty onto your computer just by arriving. Any ideas??

lbhomer2006 | Thursday, Apr 17

I am totally fed up with this type of scam.

Needless to say, if your running Windoze, DO NOT click the link!

After receiving this message this morning, I found that a program had hung and I had to use task manager to kill it.

I immediately did a search and found this blog (amongst others) and blocked the skype user "Software Warning ®" ...the trouble is there is a long list of Skype Names for that, if you click Search on the Contacts tab and search for "software.warning" you will get a long list of results.

I suggest that people use, "Tools", "Options", "Privacy", "Blocked Users" and enter "software.warning*" (I am assuming that * acts as a wildcard with Skype Names, but have not actually checked that).

I thought I would find out the whois info for this latest incarnation, so used the excellent networksolutions whois utility (thank you networksolutions!):

http://www.networksolutions.com/whois/results.jsp?domain=onlinemon.info
I am going to see what other actions I can do to follow up and try to stop this sort of crap from happening for other users, as I do not want to restrict Skype to only receive messages from contacts. Think I may well switch to using it on one of my Macs, just in case!

Here is the whois output for reference. People knowingly, helping these scammers should be "shot at dawn"... those unknowingly doing so, should take their own legal steps against the offenders!!!!

Access to INFO WHOIS information is provided to assist persons in
determining the contents of a domain name registration record in the
Afilias registry database. The data in this record is provided by
Afilias Limited for informational purposes only, and Afilias does not
guarantee its accuracy. This service is intended only for query-based
access. You agree that you will use this data only for lawful purposes
and that, under no circumstances will you use this data to: (a) allow,
enable, or otherwise support the transmission by e-mail, telephone, or
facsimile of mass unsolicited, commercial advertising or solicitations
to entities other than the data recipient's own existing customers; or
(b) enable high volume, automated, electronic processes that send
queries or data to the systems of Registry Operator, a Registrar, or
Afilias except as reasonably necessary to register domain names or
modify existing registrations. All rights reserved. Afilias reserves
the right to modify these terms at any time. By submitting this query,
you agree to abide by this policy.

Domain ID:D22731615-LRMS
Domain Name:ONLINEMON.INFO
Created On:09-Dec-2007 14:12:14 UTC
Last Updated On:07-Feb-2008 20:32:28 UTC
Expiration Date:09-Dec-2008 14:12:14 UTC
Sponsoring Registrar:MIT (R141-LRMS)
Status:OK
Registrant ID:C119714022432557
Registrant Name:Andrej Kazanski
Registrant Organization:Private Registration US
Registrant Street1:P O Box 99800
Registrant Street2:
Registrant Street3:
Registrant City:EmeryVille
Registrant State/Province:CA
Registrant Postal Code:94662
Registrant Country:US
Registrant Phone:+1.5105952002
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email:contact@myprivateregistration.com
Admin ID:D119714419035935
Admin Name:Admin PrivateRegContact
Admin Organization:Private Reg US
Admin Street1:P O Box 99800
Admin Street2:
Admin Street3:
Admin City:EmeryVille
Admin State/Province:CA
Admin Postal Code:94662
Admin Country:US
Admin Phone:+1.5105952002
Admin Phone Ext.:
Admin FAX:
Admin FAX Ext.:
Admin Email:contact@myprivateregistration.com
Billing ID:C119714022432556
Billing Name:Bill PrivateRegContact
Billing Organization:Private Reg US
Billing Street1:P O Box 99800
Billing Street2:
Billing Street3:
Billing City:EmeryVille
Billing State/Province:CA
Billing Postal Code:94662
Billing Country:US
Billing Phone:+1.5105952002
Billing Phone Ext.:
Billing FAX:
Billing FAX Ext.:
Billing Email:contact@myprivateregistration.com
Tech ID:D119714419035936
Tech Name:TECH PrivateRegContact
Tech Organization:Private Reg US
Tech Street1:P O Box 99800
Tech Street2:
Tech Street3:
Tech City:EmeryVille
Tech State/Province:CA
Tech Postal Code:94662
Tech Country:US
Tech Phone:+1.5105952002
Tech Phone Ext.:
Tech FAX:
Tech FAX Ext.:
Tech Email:contact@myprivateregistration.com
Name Server:NS1.EASYDNS.COM
Name Server:NS2.EASYDNS.COM
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:

The previous information has been obtained either directly from the registrant or a registrar of the domain name other than Network Solutions. Network Solutions, therefore, does not guarantee its accuracy or completeness.

Show underlying registry data for this record

IP Address: 64.226.42.79 (ARIN & RIPE IP search)
IP Location: US(UNITED STATES)-ARIZONA-ISSAQUAH
DMOZ no listings
Y! Directory: see listings
Web Site Title: System Scan - PLEASE WAIT - Scan in progress
Data as of: 14-Jun-2005


richuk_usa | Sunday, Apr 27

I also received this message like an hour ago...and it is trying to make me purchase a 19dollars download to remove a backdoor virus and trojan.

Is there anything I need to do so I will not get any spam message in skype.


supernaturalwarriors | Tuesday, May 20

I received this message a minute ago..

Repair Service ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.registryservice.org/?q=scan

rama.dinavahi | Wednesday, Sep 10

I just had the same message pop up. The user should be shut down for spamming/promoting malware. The username was Update(R), in case no one else posted the name.

gazma18 | Thursday, Sep 18

Well this one was new. I expected it to be one of the sex site bots. What I do not understand is why skype hasn't put a stop to this. I assume these bots are sending out thousand's of ims on each account till they get stopped for spamming. Why can't there be a threshold put in place. Just limit the amount of im's to non friended users. Keep it down at like 100 a day. That should likely be high enough to not ever effect real users and put a damper on the spammer. Not to mention give a little break as the spammers we work their bots.

quiet.thunders | Wednesday, Sep 24

I received this today.

[5:29:50 PM] Online Monitor ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.registryservice.org/?q=scan

greg.davis9 | Wednesday, Oct 1

Message still being sent. My mother got it a few weeks ago, another friend got it today.

Hopefully Skype can come up with a cure for this. I had seen some "pretty pictures" early on, and am glad for them to be gone, thanks.

What I don't understand, is how the message shows up from a contact not in the contact list, that hasn't gone through the "add me to your contact list" routine?

glenn_skype | Thursday, Jan 22

Just got this message from user named 'Registry Update':
~*~*~*~*~

[12:45:28 PM] Registry Update: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http: // www.onlineregscan .org /?q=scan

~*~*~*~*~
I'm very new to Skype, I'm glad I checked here first!

mudpupmona | Friday, Apr 17

This annoyance just visited me, it is a very amateurish attempt. Since I did not follow the link, I have no idea what nasty this link tries to load?

pauljmead | Monday, Apr 20

I got this malware alert today and blocked the user and reported the abuse.

[5:22:25 PM] Online Check: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.regscan.cc/?q=scan

Thank God. I looked at this blog before I proceeded further.

datta.ajjampur | Wednesday, May 6

Comment on this post

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Please read our comment guidelines before posting your comment.

Skype Blogs
  • Share Skype Blog
  • Heartbeat
  • Developer Zone
  • Business
  • Skype Gear
  • Security
  • Garage
  • Mac
  • Linux
  • Eesti keeles
  • 日本語
  • Česky
  • Deutsch
  • Français
  • Italiano
  • Brasil
  • United Kingdom
  • Polski
  • United States
  • 한국어

Recent posts

  • Cross-Site Request Forgery (CSRF) Vulnerability
  • Skype Lottery Scam Alert
  • [RESOLVED] Phishing emails
  • Skype misidentified as malware
  • Trojan downloader alert
  • Skype cross-zone scripting vulnerability now fixed
  • (Resolved) Skype Cross Zone Scripting Vulnerability
  • Vulnerability in Skype for Windows versions older than 3.6.x.216
  • Password stealer
  • Fake malware alert

Archives

  • April 2009
  • December 2008
  • July 2008
  • April 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • February 2007
  • January 2007
  • December 2006
  • May 2006
  • March 2006
  • February 2006
  • October 2005
  • May 2005

Subscribe to this blog
What? Tell me more…

using RSS Subscribe
via Bloglines Subscribe in Bloglines
using Newsgator Subscribe in NewsGator Online
with MyYahoo
with Google Add to Google
with MyAOL Add to My AOL
with netvibes Add to Netvibes
About us · Partners · Jobs · Prices · Security
Privacy policy · Legal · © 2009 Skype Limited