Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 30th, 2004, 09:29 PM
Marianna's Avatar
Marianna Marianna is offline
Spyware Fighter
 
Join Date: Apr 2002
Location: B.C. Canada
Posts: 1,215
Default W32/Netsky-R


Type
Win32 worm

At the time of writing, Sophos has received just one report of this worm from the wild.


Description
W32/Netsky-R is a mass mailing worm. A detailed description will be published here shortly.

http://www.sophos.com/virusinfo/anal...32netskyr.html
__________________
Microsoft MVP - Consumer Security 2006 - 2010
  #2  
Old March 30th, 2004, 10:28 PM
Marianna's Avatar
Marianna Marianna is offline
Spyware Fighter
 
Join Date: Apr 2002
Location: B.C. Canada
Posts: 1,215
Default Re:W32/Netsky-R


I-Worm/Netsky.R
Installation:
When the worm is launched, it copies itself as sysmonxp.exe to Windows Directory and registers itself as sysmonxp in Run key in Windows Registry. Worm creates firewallloger.txt file and zipo0.txt, zipo1.txt, zipo2.txt, zipo3.txt, zippedbase64.tmp and base64.tmp help files in same directory. Then it launches notepad.exe too.

Spreading: e-mail
Worm spreads by sending itself to e-mail addresses that are taken from files with xml, wsh, jsp, msg, oft, sht, dbx, tbb, adb, dhtm, cgi, shtm, uin, rtf, vbs, doc, wab, asp, php, txt, eml, html, htm and pl extension.

Message format is as following:
Sender address is faked.

Message subject and body are variable.

Message attachment name is random and could be zip archive or with executable extension.

http://www.grisoft.com/virbase/virba...6fda676cae3000
__________________
Microsoft MVP - Consumer Security 2006 - 2010
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:32 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums