Dorkbot virus doing the rounds on skype

JerryMungo

Honorary Master
Joined
Jul 18, 2008
Messages
37,561
Reaction score
6,314
Got a link from a colleague - basically they were infected and Skype started sending links to download the virus from their PC to their colleagues. The message looks like this:

lol is this your new profile pic? http://goo.gl/??????profile=xxxxxxxx
Where xxxxxxx is your skype user name. Note the url has been edited and sanitized.

Crazy thing is that 3 / 44 antivirus engines detect it as malicious on virustotal yet it's apparently quite serious:
http://thenextweb.com/microsoft/201...r-new-profile-pic-ransomware-and-click-fraud/

Well known engines that appear to detect it: Kapersky, McAffee
 
Last edited:
Got Skype users on your Network? Read it's IMPORTANT!

I am now running wild between all our users on our network solving the issue where people downloaded the .rar folder and running virus scans all over the network, so i have a long day awaiting myself so i though i'll just alert you guys as well who use skype.

Read Below:

Skype worm spreading via 'lol profile pic' messages
October 9, 2012 11:28am

Skype users were warned Tuesday (Manila time) against responding to malicious unsolicited instant messages that seek to infect computers running Microsoft's Windows operating system.

In a blog post, security vendor Sophos said the worm exploits Skype's API to spam messages that claim, "lol is this your new profile pic?," along with a link.

"Clicking on the suspicious links leads to the download of a ZIP file (variously called skype_06102012_image.zip or skype_08102012_image.zip) that contains executable files detected by Sophos anti-virus products as Troj/Agent-YCW or Troj/Agent-YDC," it said.

"The danger is, of course, that Skype users may be less in the habit of being suspicious about links sent to them than, say, Facebook users," it added.

Once installed, the Trojan horse opens a backdoor to let a remote hacker take control of the infected PC, and communicates with a remote server via HTTP.

Sophos said there had been many variants of the Dorkbot attack in the last year, spreading via Facebook and Twitter, as well as USB drives and instant messaging.
 
Got a link from a colleague - basically they were infected and Skype started sending links to download the virus from their PC to their colleagues. The message looks like this:

Where xxxxxxx is your skype user name. Note the url has been edited and sanitized.

Crazy thing is that 3 / 40 detect it as malicious on virustotal yet it's apparently quite serious:
http://thenextweb.com/microsoft/201...r-new-profile-pic-ransomware-and-click-fraud/

Yip, ESET missed it yesterday morning (think they have updated since then). So I spent the whole day cleaning colleagues computers. I also came to the conclusion that 90% of the people I work with are idiots, as they all happily clicked on the link and ran the exe file that downloaded without thinking twice.
 
Yip, ESET missed it yesterday morning (think they have updated since then). So I spent the whole day cleaning colleagues computers. I also came to the conclusion that 90% of the people I work with are idiots, as they all happily clicked on the link and ran the exe file that downloaded without thinking twice.

Need a Tsar Bomba? :D
 
Yip, ESET missed it yesterday morning (think they have updated since then). So I spent the whole day cleaning colleagues computers. I also came to the conclusion that 90% of the people I work with are idiots, as they all happily clicked on the link and ran the exe file that downloaded without thinking twice.

Dorkbot... how appropriate :)

Message sent to our more tech colleagues at work - others may find it useful:

Step by step manual instructions for removing the Skype ‘Dorkbot’ virus doing the rounds:

If you suspect a computer is infected with this virus – symptoms are that you or someone else receives a skype message from them with the following text:

lol is this your new profile pic? http://goo.gl/??????profile=xxxxxxxx

You can follow these steps to remove the virus manually on the infected PC:

1) Open Skype. Click Tools – options – advanced. Click Manage other programs’ access to Skype at the bottom
dorkbot1.jpg


2) Remove any references to suspect programs in the API Access control window. The virus usually appears as an exe file with 3-4 random character name as in the example below. Select each one and ‘remove’
dorkbot2.jpg


3) Open the ‘run’ window (press windows key and R). Enter ‘%appdata% in the ‘Open’ dialog box and click OK:
dorkbot3.jpg


4) Scroll down to the list of files in the folder (ignore other folders). Delete suspect looking executable files – usually 3-4 digit random names as in the example below:
dorkbot4.jpg


*You may receive a message to the effect that a file is in use and cannot be deleted. In this case, you need to find it in task manager and terminate it under processes:
Press Ctrl-Alt-Del and start task manager, or (if supporting the PC remotely), open the run dialog as above and enter ‘taskmgr’ to start task manager.
Click the ‘Processes’ tab and find the exe that could not be deleted in the list, select it and click ‘End Process’. Try deleting the file again.

5) There may be another random exe in the folder with a skype icon – this is the spawn process for the main virus – delete it as well. It usually has a longer name with random characters but can be identified as having the skype icon.

6) Open msconfig (open the run dialog and enter ‘msconfig’). Go to the startup tab and find a suspect entry with the name of the file in step 5. To properly identify it, you will notice in the command column, the user’s profile folder will be listed along with the file name – usually C:\users\username\appdata\roaming\ jnxkxt.exe where the jnkxt.exe could differ from computer to computer. Deselect this entry.

You may want to double check the %appdata% folder as well as Skype API access control again before rebooting the PC. After a reboot the PC should be clear of infection.
 
After learning about RATS and crypting. I absolutely refuse to use Windows as a desktop at work. There is no such thing as an AV that can protect you. Its that simple. The only thing AVs can do is try keep up to a crypt that is several weeks old. By then the drive-by is done and you are pwned.
 
After learning about RATS and crypting. I absolutely refuse to use Windows as a desktop at work. There is no such thing as an AV that can protect you. Its that simple. The only thing AVs can do is try keep up to a crypt that is several weeks old. By then the drive-by is done and you are pwned.

I think it would be great for the community to have a thread on RATs and crypting ;)
 
Anyone know of a decent free tool to remove this thingy?
 
Top
Sign up to the MyBroadband newsletter
X