Trojan downloader alert
By
Villu Arak on February 27, 2008 in Trojans and viruses.
We've seen some instances where a chat message masquerading as a link to an image file instead leads to a piece of malware. The chat messages may look similar to this:

If you receive something like this through a Skype chat message, do not be alarmed. Instead, ignore it and block the sender. Do not click on the link or open the file that the link points to.
When executed, however, the Trojan downloader creates a Microsoft Studio Files folder in the Program Files directory, populating it with a copy of itself (lsass.exe) as well as a script file (vcdg.bat) that helps it bypass the Windows firewall. The program also changes the Windows registry to enable automatic execution upon Windows startup and to bypass the Windows firewall. Following these steps, the program downloads files into the infected system.
The Skype security team would like to remind users to keep their antivirus software updated and maintain a skeptical eye toward chat messages that don't seem quite right and contain internet links, whether they appear to come from friends or total strangers.





Comments
Sype do not work.Internet works
anzelmasv | Saturday, Mar 15
There is a user who possibly needs being blocked, his/her ID is Registry Update ® (yes!). I am breaking the link, with two spaces, so that no one clikcs it.
[1:44:25 PM] Registry Update ® wrote: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================
ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003
Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns
Recommendation: Users running vulnerable version should install a repair
utility immediately
Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.
ht tp://www.onlin emonitor.info/?q=sca
bipodos_apteros | Monday, May 19
I saw the same CHAT message as anzelmasv pop up a few minutes ago.
The Complete URL it points to is :
http://www.onlinemonitor.info/?q=scan
WARNING - this is a SCAM - do not click.
It was rather strange to see a Windows virus warning pop up on my Linux (XUbuntu) machine!
I do run Skype for Linux.
netwallah | Friday, May 23
Yea, BE WARY IF THIS USER I HAD SAME THING COME IN BELOW
SKYPE - DELETE THIS USER!
[8:05:15 PM] Registry Update ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================
ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows NT Server 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Win98
Microsoft Windows Server 2003
Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns
Recommendation: Users running vulnerable version should install a repair
utility immediately
Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.
http://www.olinemonitor.info/?q=scan (EDITED LINK)
dreamstarmusic | Saturday, May 24
I just e-mailed security@skype.com about this but in case someone sees this message before they get to it, I just got a similar message from "AlertScan ®". I will break the link in the copy/paste below.
Even though I'm on my iMac they tried to tell me that:
WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================
ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003
Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns
Recommendation: Users running vulnerable version should install a repair
utility immediately
Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.
http://www.reg --BREAKING LINK-- istryupdate.org/?q=scan
avenashs | Wednesday, Jun 11
whenever I recieve a file from one of my contacts, I get a message about the risk of files perhaps containing virusses. This I am aware of, however, how do I ensure that the file is virus free using my AV I have installed? Skype does not offer this option. If I could scan the file before opening / acceptine / saving to my disc, I would avoid this problem almost entirely.
thank you cococalm@bluewin.ch
cococalm | Monday, Jul 21
Hi to all bright Skype fans! The new version of the same scam came to me Yesterday, 9/11/08. It's with the same containment but this time the URL is www.registryservice.org/?q=scan I did received many "firewall alerts" with suggestion to scan my PC because it is infected. I ignored them and I think this is the same evil person but now spreading mall ware through Skype. In Florida we say: No passaran!
peter.tomov1 | Friday, Sep 12
I received a similar message from online.monitor.papa018
18 Sept '08 at 12:02 Pacific Daylight Time (GMT-7:00)
traceykobayashi | Thursday, Sep 18
And I got the same from online.monitor.papa06
skype, you'd better get rid of all the "online.monitor.*" users
jdalleniii | Sunday, Sep 21
I just got it too(oct,2,08).. just figured you all would like to know..
I copied it below:
[12:04:25 PM] Online Service ® says:
WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================
ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003
Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns
Recommendation: Users running vulnerable version should install a repair
utility immediately
Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.
talxie | Thursday, Oct 2
oh yeah and it was from online.service.fdsfds
talxie | Thursday, Oct 2
Have this, from online.update.hagi9 Broke the link in case someone accidentally clicked it.
Update Online ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================
ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003
Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns
Recommendation: Users running vulnerable version should install a repair
utility immediately
Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.
http://www. registryservice.org/?q=scan
big.d01 | Friday, Oct 3
I received the same chat message from Registry Update ®. I blocked the user. Thanks for this discussion.
micova.net | Monday, Oct 6
I just got the same chat message from Online Update as well...thanks for the multiple posts. I'm glad I checked here before I clicked the link. I've already blocked this user..Thanks guys!!!
candace.alfred | Tuesday, Oct 14
I received this today...the ID was from
System.Notice.Gaga10
...and the message was
[4:24:47 PM] System Notice ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================
ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003
Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns
Recommendation: Users running vulnerable version should install a repair
utility immediately
Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.
http://www.#########################.org/?q=scan
jeremiahjw | Wednesday, Oct 15
We had a similar problem with a user named online.monitor.papa06. It also gave this pop up message:
[4:24:47 PM] System Notice ® says: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================
ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003
Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns
Recommendation: Users running vulnerable version should install a repair
utility immediately
Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.
NOTE: I did not post the link for security reasons.
What we did to handle it was as follows:
1. Block the user on Skype. This had to be done on any computer that had a conversation with the infected user. (If you are chatting with a person who has the online.monitor.papa06, you'll see it added as an extra participant in the chat. Right click on it, and select BLOCK.
2. Deleted all history from Skype (on all computers connected or chatted with).
3. Ran AVG 8.0 Antivirus (Sunbelt and Kaspersky will work too, but AVG is free) and scanned computer for threat. Removed trojan downloader.
4. Make sure to scan all computers connected to the infected computer, including ones involved in remote conversations.
This virus was not terribly difficult to remove, it was more annoying than anything. Just be careful what you click on!!
www.jerseyshorecomputer.net
jerseyshorecomputer | Monday, Oct 20
I just got the same message from a user named Online Check® - going to block and follow the procedures others have recommended.
lesleymenchions | Thursday, Nov 20
Online Registry ®
12:15 PM
WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================
ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003
Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns
Recommendation: Users running vulnerable version should install a repair
utility immediately
Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.
http://www.registryscan.cc/?q=scan
itstimo | Friday, Nov 28
I AM SO SORRY I DID NOT MEAN TO POST THE LINK! PLEASE DO NOT CLICK IT, IT IS SERIOUSLY BAD NEWS! SORRY EVERYONE!
itstimo | Friday, Nov 28
Yeah I also got something like this:
[7:30:47 AM] Check Online: WINDOWS REQUIRES IMMEDIATE ATTENTION
=============================
ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT Server 4.0
Microsoft Windows Win98
Microsoft Windows Server 2003
Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns
Recommendation: Users running vulnerable version should install a repair
utility immediately
Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.
ht [...] tp://www.onlinecheck.cc/?q=scan
dbestarchitect | Saturday, May 9
Hey guys,
thanks for that info. I never open links in chats neighter in Messenger. Does this apply at every version of Skype? I am currently running 3.8.0.188, but I think I will (re)-upgrade soon to 4.1.
Bye!
Michele Barbi from Italy (Skype ID comes from a Green day song)
american_idiot5178 | Thursday, Sep 3
In the past week I have received two similar Skype conversations purporting to be online notifications that a contact with the name of online.notification.america20 is not in my contact list and needs to be included. It also directs me to use a link (http://www.updatert.org) to accomplish this. I have a screen print of this message if you want to see the message. This is very unusual and seems similar to other contact phishing exploits used in other areas. I have blocked this user and reported it as abuse.
rooscow | Thursday, Oct 22
While I talked to a land line telephone, the similar message "ATTENTION ! Security Center has detected..." popped up. Before I stopped talking, I noticed my Skype account was popped up and an unknown scanning program start running on my pc. I immediately shot my PC down and then run McAfee full scan. Hopefully everything will be all right after the scan. I hope that the Skype security team is monitoring the issue.
cicciabc | Thursday, Oct 29