Skype Logo Take a deep breath™.
Buy Skype Credit · Help ·
  • Download
  • Use Skype
  • Business
  • Shop
  • Account
Villu Arak

Password stealer

By My status Villu Arak on December 6, 2007 in Impersonation.

passwordstealer4.png

Looks like virus writers are at it again. Some Skype users have been contacted over chat by people warning against viruses and offering to send the user a file that masquerades as Spyware Doctor, a popular anti-malware program from PC Tools. Needless to say, the file they’re attempting to send (SpyWareDoctorSetup.exe) is not the real thing. Instead, it’s a piece of malware, affecting Windows users. Do not accept or run this executable file.

passwordstealer1.png

From what we understand, this malware likely belongs to the same family with previous password stealers. The behavior is exactly the same, only this time it disguises itself as Spyware Doctor. The setup process of the genuine Spyware Doctor is completely different.

When executed, the fake version displays the “Welcome” screen and promptly shuts down Skype. When the unsuspecting user presses the “Next” button, the program briefly displays a fake installation screen (in reality, no installation takes place) and then immediately displays the “Skype login” screen.

When the user enters his username and password, an error message is displayed — regardless of whether the password was correct or not. In the background, however, the entered login details are sent to a malicious web server. In addition, the program reads Internet Explorer’s saved forms and passwords stored in Windows protected storage and sends them along as well. It does not read stored information in any other web browser.

Clicking on the “Close X” button or the standard close window button in the upper right corner of window does not close the program. You can only terminate the program from the Windows Task Manager.

The malware is a password stealer and does not interact with Skype in any way. It does not leave a resident in memory, modify any Windows DLLs, inject threads into existing services, or try to survive reboot (there is no modification of the Registry or existing registered services). And the program does not attempt to distribute itself in any way. In fact, it seems to be spread by real people using Skype chat, as there is no evidence that the process is automated.

So, if you’ve unwittingly fallen victim to this password stealer, here’s how to disinfect your machine manually:

  • Double click on the Windows taskbar to open Task Manager
  • Select the Processes tab
  • Find SpyWareDoctorSetup.exe from the list
  • Click on End Process button

Delete SpyWareDoctorSetup.exe from the file system (use Search For Files and Folders to find the location in case you don’t remember where you saved it).

View blog reactions

Comment on this post

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Skype Blogs
  • Share Skype Blog
  • About Skype
  • Heartbeat
  • Developer Zone
  • Business
  • Jobs
  • Skype Prime
  • Skype Gear
  • Security
  • Garage
  • Mac
  • Linux
  • Eesti keeles
  • Töökuulutuste leht
  • 日本語
  • Deutsch
  • Français
  • Italiano
  • Brasil
  • United Kingdom
  • Svenska
  • Polski

Recent posts

  • Trojan downloader alert
  • Skype cross-zone scripting vulnerability now fixed
  • (Resolved) Skype Cross Zone Scripting Vulnerability
  • Vulnerability in Skype for Windows versions older than 3.6.x.216
  • Password stealer
  • Fake malware alert
  • Skype for Mac on Leopard
  • Updated: Malware alert
  • Skype Defender malware alert
  • Skype Extras plug-in manager

Archives

  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • February 2007
  • January 2007
  • December 2006
  • May 2006
  • March 2006
  • February 2006
  • October 2005
  • May 2005

Subscribe to this blog
What? Tell me more…

using RSS Subscribe
via Bloglines Subscribe in Bloglines
using Newsgator Subscribe in NewsGator Online
with MyYahoo
with Google Add to Google
with MyAOL Add to My AOL
with netvibes Add to Netvibes
About us · Partners · Jobs · Prices · Security
Privacy policy · Legal · © 2008 Skype Limited