A security researcher has reported in his blog, Bkis Blog, that a new worm is spreading in Yahoo Messenger and Skype.
The malware, which Bkis has detected as “W32.Skyhoo.Worm,” disappears if the computer does not have Skype or Yahoo Messenger installed. It automatically sends messages with varying content and malicious links to contacts in the victim’s IM list and automatically injects a malicious link in e-mail messages and Word or Excel files that the user is composing, Bkis said.

YM and Skype users are sent a message link with a message such as “Does my new hair style look good? bad? perfect?” or “My printer is about to be thrown through a window if this pic won’t come out right. You see anything wrong with it?”.
Once the user has click the link it will forward it to cloak rapidshare.com for downloading of a zip file that contains the jpg file but the file is actually not a picture file but rather a com executable file. Once the file has been installed it will send messages from the YM contact lists and injects the message and url.
In order to prevent this worm from spreading is to update your anti-virus and antispyware softwares and stop clicking url even if the sender is listed in your contact file.
Click here for a list of free antispyware downloads.