Skype Logo
Buy Skype Credit · Help ·
  • Download
  • Use Skype
  • Business
  • Shop
  • Account
Villu Arak

Trojan downloader alert

By My status Villu Arak on February 27, 2008 in Trojans and viruses.

We've seen some instances where a chat message masquerading as a link to an image file instead leads to a piece of malware. The chat messages may look similar to this:

galvao.png

If you receive something like this through a Skype chat message, do not be alarmed. Instead, ignore it and block the sender. Do not click on the link or open the file that the link points to.

When executed, however, the Trojan downloader creates a Microsoft Studio Files folder in the Program Files directory, populating it with a copy of itself (lsass.exe) as well as a script file (vcdg.bat) that helps it bypass the Windows firewall. The program also changes the Windows registry to enable automatic execution upon Windows startup and to bypass the Windows firewall. Following these steps, the program downloads files into the infected system.

The Skype security team would like to remind users to keep their antivirus software updated and maintain a skeptical eye toward chat messages that don't seem quite right and contain internet links, whether they appear to come from friends or total strangers.

Bookmark and Share

View blog reactions

Comments

Sype do not work.Internet works

anzelmasv | Saturday, Mar 15

There is a user who possibly needs being blocked, his/her ID is Registry Update ® (yes!). I am breaking the link, with two spaces, so that no one clikcs it.

[1:44:25 PM] Registry Update ® wrote: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

ht tp://www.onlin emonitor.info/?q=sca

bipodos_apteros | Monday, May 19

I saw the same CHAT message as anzelmasv pop up a few minutes ago.

The Complete URL it points to is :
http://www.onlinemonitor.info/?q=scan
WARNING - this is a SCAM - do not click.

It was rather strange to see a Windows virus warning pop up on my Linux (XUbuntu) machine!

I do run Skype for Linux.

netwallah | Friday, May 23

Yea, BE WARY IF THIS USER I HAD SAME THING COME IN BELOW

SKYPE - DELETE THIS USER!

[8:05:15 PM] Registry Update ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.olinemonitor.info/?q=scan (EDITED LINK)

dreamstarmusic | Saturday, May 24

I just e-mailed security@skype.com about this but in case someone sees this message before they get to it, I just got a similar message from "AlertScan ®". I will break the link in the copy/paste below.

Even though I'm on my iMac they tried to tell me that:

WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.reg --BREAKING LINK-- istryupdate.org/?q=scan

avenashs | Wednesday, Jun 11

whenever I recieve a file from one of my contacts, I get a message about the risk of files perhaps containing virusses. This I am aware of, however, how do I ensure that the file is virus free using my AV I have installed? Skype does not offer this option. If I could scan the file before opening / acceptine / saving to my disc, I would avoid this problem almost entirely.

thank you cococalm@bluewin.ch

cococalm | Monday, Jul 21

Hi to all bright Skype fans! The new version of the same scam came to me Yesterday, 9/11/08. It's with the same containment but this time the URL is www.registryservice.org/?q=scan I did received many "firewall alerts" with suggestion to scan my PC because it is infected. I ignored them and I think this is the same evil person but now spreading mall ware through Skype. In Florida we say: No passaran!

peter.tomov1 | Friday, Sep 12

I received a similar message from online.monitor.papa018

18 Sept '08 at 12:02 Pacific Daylight Time (GMT-7:00)

traceykobayashi | Thursday, Sep 18

And I got the same from online.monitor.papa06

skype, you'd better get rid of all the "online.monitor.*" users

jdalleniii | Sunday, Sep 21

I just got it too(oct,2,08).. just figured you all would like to know..
I copied it below:

[12:04:25 PM] Online Service ® says:
WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

talxie | Thursday, Oct 2

oh yeah and it was from online.service.fdsfds

talxie | Thursday, Oct 2

Have this, from online.update.hagi9 Broke the link in case someone accidentally clicked it.

Update Online ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www. registryservice.org/?q=scan

big.d01 | Friday, Oct 3

I received the same chat message from Registry Update ®. I blocked the user. Thanks for this discussion.

micova.net | Monday, Oct 6

I just got the same chat message from Online Update as well...thanks for the multiple posts. I'm glad I checked here before I clicked the link. I've already blocked this user..Thanks guys!!!

candace.alfred | Tuesday, Oct 14

I received this today...the ID was from
System.Notice.Gaga10

...and the message was

[4:24:47 PM] System Notice ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.#########################.org/?q=scan

jeremiahjw | Wednesday, Oct 15

We had a similar problem with a user named online.monitor.papa06. It also gave this pop up message:

[4:24:47 PM] System Notice ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

NOTE: I did not post the link for security reasons.

What we did to handle it was as follows:

1. Block the user on Skype. This had to be done on any computer that had a conversation with the infected user. (If you are chatting with a person who has the online.monitor.papa06, you'll see it added as an extra participant in the chat. Right click on it, and select BLOCK.
2. Deleted all history from Skype (on all computers connected or chatted with).
3. Ran AVG 8.0 Antivirus (Sunbelt and Kaspersky will work too, but AVG is free) and scanned computer for threat. Removed trojan downloader.
4. Make sure to scan all computers connected to the infected computer, including ones involved in remote conversations.

This virus was not terribly difficult to remove, it was more annoying than anything. Just be careful what you click on!!

www.jerseyshorecomputer.net

jerseyshorecomputer | Monday, Oct 20

I just got the same message from a user named Online Check® - going to block and follow the procedures others have recommended.

lesleymenchions | Thursday, Nov 20

Online Registry ®
12:15 PM
WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

http://www.registryscan.cc/?q=scan

itstimo | Friday, Nov 28

I AM SO SORRY I DID NOT MEAN TO POST THE LINK! PLEASE DO NOT CLICK IT, IT IS SERIOUSLY BAD NEWS! SORRY EVERYONE!

itstimo | Friday, Nov 28

Yeah I also got something like this:

[7:30:47 AM] Check Online: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair
utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

ht [...] tp://www.onlinecheck.cc/?q=scan

dbestarchitect | Saturday, May 9

Hey guys,
thanks for that info. I never open links in chats neighter in Messenger. Does this apply at every version of Skype? I am currently running 3.8.0.188, but I think I will (re)-upgrade soon to 4.1.
Bye!
Michele Barbi from Italy (Skype ID comes from a Green day song)

american_idiot5178 | Thursday, Sep 3

In the past week I have received two similar Skype conversations purporting to be online notifications that a contact with the name of online.notification.america20 is not in my contact list and needs to be included. It also directs me to use a link (http://www.updatert.org) to accomplish this. I have a screen print of this message if you want to see the message. This is very unusual and seems similar to other contact phishing exploits used in other areas. I have blocked this user and reported it as abuse.

rooscow | Thursday, Oct 22

While I talked to a land line telephone, the similar message "ATTENTION ! Security Center has detected..." popped up. Before I stopped talking, I noticed my Skype account was popped up and an unknown scanning program start running on my pc. I immediately shot my PC down and then run McAfee full scan. Hopefully everything will be all right after the scan. I hope that the Skype security team is monitoring the issue.

cicciabc | Thursday, Oct 29

Comment on this post

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Please read our comment guidelines before posting your comment.

Skype Blogs
  • Share Skype Blog
  • Heartbeat
  • Developer Zone
  • Business
  • Skype Gear
  • Security
  • Garage
  • Mac
  • Linux
  • Eesti keeles
  • 日本語
  • Česky
  • Deutsch
  • Français
  • Italiano
  • Brasil
  • United Kingdom
  • Polski
  • United States
  • 한국어

Recent posts

  • A little bit about Trojan.Peskyspy
  • Cross-Site Request Forgery (CSRF) Vulnerability
  • Skype Lottery Scam Alert
  • [RESOLVED] Phishing emails
  • Skype misidentified as malware
  • Trojan downloader alert
  • Skype cross-zone scripting vulnerability now fixed
  • (Resolved) Skype Cross Zone Scripting Vulnerability
  • Vulnerability in Skype for Windows versions older than 3.6.x.216
  • Password stealer

Archives

  • September 2009
  • April 2009
  • December 2008
  • July 2008
  • April 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • February 2007
  • January 2007
  • December 2006
  • May 2006
  • March 2006
  • February 2006
  • October 2005
  • May 2005

Subscribe to this blog
What? Tell me more…

using RSS Subscribe
via Bloglines Subscribe in Bloglines
using Newsgator Subscribe in NewsGator Online
with MyYahoo
with Google Add to Google
with MyAOL Add to My AOL
with netvibes Add to Netvibes
About us · Partners · Jobs · Prices · Security
Privacy policy · Legal · © 2009 Skype Limited