Sophos

W32/Netsky-A

Aliases
  • Win32/Netsky.A
Category
Type
What to do
Prevalence low high

Summary

 
Protection available since 19 February 2004 12:01:34 (GMT)
Last updated 21 April 2004 08:57:54 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.

Windows NT/2000/XP/2003

In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
service= "C:\\WINDOWS\\services.exe -serv

and delete it if it exists.

Close the registry editor.

More Information

W32/Netsky-A is a worm that spreads using email and Windows network shares.

W32/Netsky-A searches all mapped drives for files with the following extensions in order to find email adresses: MSG, OFT, SHT, DBX, TBB, ADB, DOC, WAB, ASP, UIN, RTF, VBS, HTML, HTM, PL, PHP, TXT, EML

The worm will also attempt to copy itself into the root folders of drives C: to Z: using the following filenames:

angels.pif
coolscreensaver.scr
dictionary.doc.exe
dolly_buster.jpg.pif
doom2.doc.pif
e.book.doc.exe
e-book.archive.doc.exe
eminem-lickmypussy.mp3.pif
hardcoreporn.jpg.exe
howtohack.doc.exe
matrix.scr
maxpayne2.crack.exe
nero.7.exe
office_crack.exe
photoshop9crack.exe
porno.scr
programmingbasics.doc.exe
rfccompilation.doc.exe
serial.txt.exe
sexsexsexsex.doc.exe
strippoker.exe
virii.scr
winlonghorn.doc.exe
winxp_crack.exe

W32/Netsky-A may arrive in an email with the following characteristics:

Sender: one of -
auctions@yahoo.com
responder@ebay.com
responder@amazon.com
auctions@msn.com
responder@qxl.com
Subject line: Auction successful!

#----------------- message was sent by automail agent ------

Congratulations!

You were successful in the auction
Auction ID <random>
Product ID <random>

A detailed description about the product and the bill are attached to this mail.
Please contact the seller immediately

Thank you!

Attached file: one of -
prod_info_04155.bat
prod_info_04650.bat
prod_info_33325.txt.scr
prod_info_33462.cmd
prod_info_33543.rtf.scr
prod_info_33967.cmd
prod_info_34157.htm.exe
prod_info_42313.pif
prod_info_42314.pif
prod_info_42818.pif
prod_info_43631.doc.exe
prod_info_43859.htm.scr
prod_info_47532.doc.scr
prod_info_49146.exe
prod_info_49541.exe
prod_info_54234.scr
prod_info_54235.scr
prod_info_54433.doc.exe
prod_info_54739.scr
prod_info_55761.rtf.exe
prod_info_56474.txt.exe
prod_info_56780.doc.exe
prod_info_65642.rtf.scr
prod_info_77256.txt.scr
prod_info_87968.htm.scr

or

prod_info_04155.zip
prod_info_04650.zip
prod_info_33325.zip
prod_info_33462.zip
prod_info_33543.zip
prod_info_33967.zip
prod_info_34157.zip
prod_info_42313.zip
prod_info_42314.zip
prod_info_42818.zip
prod_info_43631.zip
prod_info_43859.zip
prod_info_47532.zip
prod_info_49146.zip
prod_info_49541.zip
prod_info_54234.zip
prod_info_54235.zip
prod_info_54433.zip
prod_info_54739.zip
prod_info_55761.zip
prod_info_56474.zip
prod_info_56780.zip
prod_info_65642.zip
prod_info_77256.zip
prod_info_87968.zip

When the file is extracted end opened the virus may display the message "The file could not be opened".

W32/Netsky-A copies itself into the Windows folder as services.exe.

In order to run automatically when Windows starts up W32/Netsky-A creates the following registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
service= "C:\\WINDOWS\\services.exe -serv

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer