<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>W32/Netsky-AC {Sophos} in Security</title>
<link>http://www.dslreports.com/forum/r10135556</link>
<description></description>
<language>en</language>
<pubDate>Fri, 04 Dec 2009 06:13:25 EDT</pubDate>
<lastBuildDate>Fri, 04 Dec 2009 06:13:25 EDT</lastBuildDate>

<item>
<title>Re: W32/Netsky-AC {Sophos}</title>
<link>http://www.dslreports.com/forum/remark,10160268</link>
<description><![CDATA[<A HREF="/useremail/u/590730"><b>Randy Bell</b></A> : McAfee: W32/Netsky.ac@MM<br>&raquo;<A HREF="http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=125016" >us.mcafee.com/virusInfo/default.&middot;&middot;&middot;k=125016</A><br><br>Computer Associates: Win32.Netsky.AC<br>&raquo;<A HREF="http://www3.ca.com/threatinfo/virusinfo/virus.aspx?ID=39026" >www3.ca.com/threatinfo/virusinfo&middot;&middot;&middot;ID=39026</A><br><br>F-Secure: NetSky.AC<br>&raquo;<A HREF="http://www.f-secure.com/v-descs/netskyac.shtml" >www.f-secure.com/v-descs/netskyac.shtml</A><br><br>Panda: Netsky.AC<br>&raquo;<A HREF="http://www.virusportal.com/com/virusinfo/encyclopedia/overview.aspx?idvirus=46889" >www.virusportal.com/com/virusinf&middot;&middot;&middot;us=46889</A><br><br>VSAntivirus: W32/Netsky.AC. Subject: "Escalation"<br>{English Transl}: &raquo;<A HREF="http://babelfish.altavista.com/babelfish/trurl_pagecontent?lp=es_en&url=http%3a%2f%2fwww.vsantivirus.com%2fnetsky-ac.htm" >babelfish.altavista.com/babelfis&middot;&middot;&middot;y-ac.htm</A><br>{Spanish Original}: &raquo;<A HREF="http://www.vsantivirus.com/netsky-ac.htm" >www.vsantivirus.com/netsky-ac.htm</A><br><SMALL>--<br><I>"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10160268</guid>
<pubDate>Wed, 05 May 2004 15:06:59 EDT</pubDate>
</item>

<item>
<title>Re: W32/Netsky-AC {Sophos}</title>
<link>http://www.dslreports.com/forum/remark,10160242</link>
<description><![CDATA[<A HREF="/useremail/u/590730"><b>Randy Bell</b></A> : Sophos has filled in the details in their writeup for this variant:<br><br> <BLOCKQUOTE><SMALL>said by Sophos:</SMALL><HR>W32/Netsky-AC is a mass mailing worm. The worm copies itself to the Windows folder as comp.cpl and creates a helper component wserver.exe in the same folder. W32/Netsky-AC sets the following registry entry to ensure it is run on user logon: <br><br>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\<br>wserver = wserver.exe <br><br>Emails sent by W32/Netsky-AC have the following characteristics: <br><br><B>Subject line:</B> <br><br>Escalation <br><br><B>Message text:</B> <br><br>Dear user of {harvested domain name} <br><br>We have received several abuses: <br><br>- Hundreds of infected e-Mails have been sent<br>from your mail account by the new worm {virus name}<br>- Spam email has been relayed by the backdoor<br>that the virus has created <br><br>The malicious file uses your mail account to distribute<br>itself. The backdoor that the worm opens allows remote attackers<br>to gain the control of your computer. This new worm<br>is spreading rapidly around the world now<br>and it is a serios new threat that hits users. <br><br>Due to this, we are providing you to remove the<br>infection on your computer and to<br>stop the spreading of the malware with a<br>special desinfection tool attached to this mail. <br><br>If you have problems with the virus removal file,<br>please contact our support team at <br><br>support@{anti-virus domain} <br><br>Note that we do not accept html email messages. <br><br>{anti-virus vendor} AntiVirus Research Team<br>Attach: Fix_{virus name}_{random number}.cpl <br><br><B>Note:</B> <br><br>{anti-virus vendor} is selected from the following: <br><br>Sophos<br>MCAfee<br>Norman<br>Norton <br><br>{anti-virus domain} is selected from the following: <br><br>sophos.com<br>symantec.com<br>nai.com<br>norman.com <br><br>{virus name} is selected from the following: <br><br>NetSky.AB<br>Sasser.B<br>Bagle.AB<br>Mydoom.F<br>MSBlast.B <br><br>Attachment Name: <br><br>Fix_{virus name}_{random number}.cpl <br><br>Sophos researchers have also discovered that hidden inside the code of Netsky-AC is the following text, directed towards anti-virus companies: <br><br>Hey, av firms, do you know that we have programmed the sasser virus?!?. Yeah thats true! Why do you have named it sasser? A Tip: Compare the FTP-Server code with the one from Skynet.V!!! LooL! We are the Skynet...<HR></BLOCKQUOTE><br><SMALL>--<br><I>"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10160242</guid>
<pubDate>Wed, 05 May 2004 15:03:43 EDT</pubDate>
</item>

<item>
<title>Re: W32/Netsky-AC {Sophos}</title>
<link>http://www.dslreports.com/forum/remark,10135647</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : FYI link to &raquo;<A HREF="/forum/remark,10111167">I-Worm.Netsky.ac {KAV}</A> <br>for continuity <br>EDIT - note that all have NETSKY.AC in their name, but the descriptions are substantially different. Nothing like more naming confusion. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10135647</guid>
<pubDate>Sun, 02 May 2004 22:28:08 EDT</pubDate>
</item>

<item>
<title>Re: W32/Netsky-AC {Sophos}</title>
<link>http://www.dslreports.com/forum/remark,10135607</link>
<description><![CDATA[<A HREF="/useremail/u/590730"><b>Randy Bell</b></A> : Trend: WORM_NETSKY.AC<br>&raquo;<A HREF="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_NETSKY.AC" >www.trendmicro.com/vinfo/virusen&middot;&middot;&middot;ETSKY.AC</A><br>Tech Details: &raquo;<A HREF="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_NETSKY.AC&VSect=T" >www.trendmicro.com/vinfo/virusen&middot;&middot;&middot;&VSect=T</A><br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR> Upon execution, this NETSKY variant drops the following files in the Windows folder: <br><br>&#8226;CCOMP.CPL &#150; a copy of itself <br>&#8226;WSERVER.EXE &#150; its memory-resident component <br><br>It creates the following registry entry so that it executes at every system startup: <br><br>HKEY_LOCAL_MACHINE\Software\Microsoft\<br>Windows\CurrentVersion\Run<br>Wserver = "%Windows%\wserver.exe" <br><br>(Note: %Windows% is the default Windows folder, usually C:\Windows or C:\WINNT.) <HR></BLOCKQUOTE><br><br><I>{See above link for tech details including email message bodies, attachments}</I><br><SMALL>--<br><I>"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10135607</guid>
<pubDate>Sun, 02 May 2004 22:23:46 EDT</pubDate>
</item>

<item>
<title>W32/Netsky-AC {Sophos}</title>
<link>http://www.dslreports.com/forum/remark,10135556</link>
<description><![CDATA[<A HREF="/useremail/u/590730"><b>Randy Bell</b></A> : I did a Search and I believe this one is new .. has not been posted yet.  There was an I-Worm.Netsky.AC {KAV} posted but upon further examination {of the discovery date and infection details} it appears to have been the same as the W32/Netsky-AB {Sophos} posted earlier .. so this seems to be a new one:<br><br>Sophos: W32/Netsky-AC<br>&raquo;<A HREF="http://www.sophos.com/virusinfo/analyses/w32netskyac.html" >www.sophos.com/virusinfo/analyse&middot;&middot;&middot;yac.html</A><br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR> Detection:<br>A virus identity (IDE) file which provides protection is available now from the Latest virus identities section .. {{~snipped~}} ..<br><br>Sophos has received many reports of this worm from the wild. <br> <br>Description <br>W32/Netsky-AC is a mass mailing worm. A detailed description will be published here shortly.<HR></BLOCKQUOTE><br><SMALL>--<br><I>"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10135556</guid>
<pubDate>Sun, 02 May 2004 22:18:00 EDT</pubDate>
</item>

</channel>
</rss>
