Skip to main content

IM-Worm:W32/Pykse.A

Classification

Category:

Malware

Type:

Im-worm

Aliases:

  • IM-Worm.Win32.Pykse.a
  • Worm.IM.Picse.A

Summary

A type of worm that spreads on vulnerable Instant Messaging (IM) networks.

Removal

Technical Details

IM-Worm:W32/Pykse.A is an instant messaging worm that uses the APIR for the Instant Messaging application Skype to send messages with malicious URL links.When IM-Worm:W32/Pykse.A is executed, it will show a picture of a lightly dressed woman as below:

Note: the image has been blurred.

Installation

When executed, the worm drops the following files:

  • %sysdir%\Invisible002.dll - contains most of malicious code
  • %sysdir%\system32\Skype.exe

It adds the following auto start registry entry to enable its automatic execution upon boot up:

  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run SkypeStartup = "%sysdir%\Skype.exe"
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SkypeStartup = "%sysdir%\Skype.exe"

It also adds the .DLL component as a BHO (Browser Helper Object) so that once the Internet browser is loaded, the malware is also loaded simultaneously.IM-Worm:W32/Pykse.A creates the following key, to save some of its installation details:

  • HKCU\Software\SkypeWorm\cfg

It creates the following mutexes to signify each malicious routine. No duplicate mutex could be created to ensure that only these three mutexes are present in the memory at one particular time:

  • Skype Worm spreader mutex - Spreading routine
  • Skype Worm server mutex1 - Other routines
  • aaa111226 - Iexplore.exe injection

Propagation

IM-Worm:W32/Pykse.A spreads via Skype by sending a message with a malware link to all online friends in Skype' contact list using Skype API.The message is randomly chosen from the following list:

It sets the Skype user's status to DND (Do not Disturb) so that the user cannot be actively notified of incoming calls or messages.It visits the following non-malicious links:

  • https://aras.lookingat.us/index.htm
  • https://asilas.my-php.net/index.html
  • https://bobodada.3-hosting.net/index.html
  • https://bobos45.bebto.com/index.html
  • https://gogo442.hatesit.com/index.html
  • https://jackdaniels.110mb.com/index.html
  • https://timboss.1majorhost.com/index.html
  • https://zozole.php0h.com/index.html

Moreover the following site is also visited, which probably acts as a counter for the number of infected machines:

  • https://aras.allfreehost.net/c[REMOVED]nt.php

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.