republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » W32/Netsky-AC {Sophos}
Search Topic:
Uniqs:
184
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
W32.Netsky.AB@mm »
« removing iSearch Toolbar  
AuthorAll Replies


Randy Bell
Premium
join:2002-02-24
Santa Clara, CA

W32/Netsky-AC {Sophos}

I did a Search and I believe this one is new .. has not been posted yet. There was an I-Worm.Netsky.AC {KAV} posted but upon further examination {of the discovery date and infection details} it appears to have been the same as the W32/Netsky-AB {Sophos} posted earlier .. so this seems to be a new one:

Sophos: W32/Netsky-AC
»www.sophos.com/virusinfo/analyse···yac.html

quote:
Detection:
A virus identity (IDE) file which provides protection is available now from the Latest virus identities section .. {{~snipped~}} ..

Sophos has received many reports of this worm from the wild.

Description
W32/Netsky-AC is a mass mailing worm. A detailed description will be published here shortly.
--
"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)


Randy Bell
Premium
join:2002-02-24
Santa Clara, CA

Trend: WORM_NETSKY.AC
»www.trendmicro.com/vinfo/virusen···ETSKY.AC
Tech Details: »www.trendmicro.com/vinfo/virusen···&VSect=T

quote:
Upon execution, this NETSKY variant drops the following files in the Windows folder:

•CCOMP.CPL – a copy of itself
•WSERVER.EXE – its memory-resident component

It creates the following registry entry so that it executes at every system startup:

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run
Wserver = "%Windows%\wserver.exe"

(Note: %Windows% is the default Windows folder, usually C:\Windows or C:\WINNT.)
{See above link for tech details including email message bodies, attachments}
--
"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)


EGeezer
Summertime -
Premium
join:2002-08-04
Country!

2 edits
reply to Randy Bell
FYI link to »I-Worm.Netsky.ac {KAV}
for continuity
EDIT - note that all have NETSKY.AC in their name, but the descriptions are substantially different. Nothing like more naming confusion.


Randy Bell
Premium
join:2002-02-24
Santa Clara, CA

reply to Randy Bell
Sophos has filled in the details in their writeup for this variant:

said by Sophos:
W32/Netsky-AC is a mass mailing worm. The worm copies itself to the Windows folder as comp.cpl and creates a helper component wserver.exe in the same folder. W32/Netsky-AC sets the following registry entry to ensure it is run on user logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
wserver = wserver.exe

Emails sent by W32/Netsky-AC have the following characteristics:

Subject line:

Escalation

Message text:

Dear user of {harvested domain name}

We have received several abuses:

- Hundreds of infected e-Mails have been sent
from your mail account by the new worm {virus name}
- Spam email has been relayed by the backdoor
that the virus has created

The malicious file uses your mail account to distribute
itself. The backdoor that the worm opens allows remote attackers
to gain the control of your computer. This new worm
is spreading rapidly around the world now
and it is a serios new threat that hits users.

Due to this, we are providing you to remove the
infection on your computer and to
stop the spreading of the malware with a
special desinfection tool attached to this mail.

If you have problems with the virus removal file,
please contact our support team at

support@{anti-virus domain}

Note that we do not accept html email messages.

{anti-virus vendor} AntiVirus Research Team
Attach: Fix_{virus name}_{random number}.cpl

Note:

{anti-virus vendor} is selected from the following:

Sophos
MCAfee
Norman
Norton

{anti-virus domain} is selected from the following:

sophos.com
symantec.com
nai.com
norman.com

{virus name} is selected from the following:

NetSky.AB
Sasser.B
Bagle.AB
Mydoom.F
MSBlast.B

Attachment Name:

Fix_{virus name}_{random number}.cpl

Sophos researchers have also discovered that hidden inside the code of Netsky-AC is the following text, directed towards anti-virus companies:

Hey, av firms, do you know that we have programmed the sasser virus?!?. Yeah thats true! Why do you have named it sasser? A Tip: Compare the FTP-Server code with the one from Skynet.V!!! LooL! We are the Skynet...
--
"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)


Randy Bell
Premium
join:2002-02-24
Santa Clara, CA


3 edits
reply to Randy Bell
McAfee: W32/Netsky.ac@MM
»us.mcafee.com/virusInfo/default.···k=125016

Computer Associates: Win32.Netsky.AC
»www3.ca.com/threatinfo/virusinfo···ID=39026

F-Secure: NetSky.AC
»www.f-secure.com/v-descs/netskyac.shtml

Panda: Netsky.AC
»www.virusportal.com/com/virusinf···us=46889

VSAntivirus: W32/Netsky.AC. Subject: "Escalation"
{English Transl}: »babelfish.altavista.com/babelfis···y-ac.htm
{Spanish Original}: »www.vsantivirus.com/netsky-ac.htm
--
"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)
Forums » Up and Running » Security » SecurityW32.Netsky.AB@mm »
« removing iSearch Toolbar  


Tuesday, 10-Nov 08:51:05 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [89] Verizon Keeps Swinging At AT&T
· [84] VoIP Over 3G Still Not Working For iPhone
· [33] Bill Would Force ISPs To Block Financial Scams
· [24] Mediacom Hints At 50, 100 Mbps Speeds
· [15] Clearwire To Get Another $1.5 Billion
· [12] Monday Evening Links
· [10] 15 States Have Now Gotten Broadband Mapping Money
· [6] AT&T Launching New 7.2 Mbps 3G Modem
· [1] Sprint Announces Job Cuts
· [0] Tuesday Morning Links
Most people now reading
· A fishy CRTC tarriff filed by bell? [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Wood floor opinion... [Home Repair & Improvement]
· 60 Minutes piece on cyber security last night [Security]
· Blown out Ballasts [Home Repair & Improvement]
· Framed for child porn 151; by a PC virus [Security]
· How in the world am I going to get into college? [General Questions]
· Dragon Age: Origins [PC gaming GAMES]