According to security firm Websense, users will receive a message asking them to download a file called "Sp.exe". This file is a Trojan program that can steal passwords. If the user activates this Trojan, it will run another script to spread to other computers.
The first infected area seems to be Asia-Pacific, especially in Korea, Websense said. The company is still investigating this incident.
Disagreements in security circles
New worms spread via Skype Picture 1Source: Gmx However, not every security firm agrees with this statement. F-Secure received a sample of the worm and concluded that in fact, it did not target Skype. "Obviously, at this point, there is no worm attack on Skype. We are still watching," said Mikko Hypponen, F-Secure's research director.
Meanwhile, the SANS Center said it is still "listening" and gathering information about new worms distributed via Skype IM. All conclusions made at the moment are "rush and uncertain".
Websense said the Skype worm file was encrypted using NTKrnl Secure Suite Packer, a state-of-the-art encryption program, so that before each virus scanner, it had a completely new cover.