English
Romana
Home
|
Contact
|
Feedback
SEARCH
Security Development
Company
Careers
Press Center
Virus Info
Security News
Virus Glossary
About Malware
VDF History
External Links
Solutions
Products
Alerts Panel
Support
Register
Worm/Netsky.D.Dam - Worm
See also
Summary
Full description
Virus:
Worm/Netsky.D.Dam
Date discovered:
01/03/2004
Type:
Worm
In the wild:
Yes
Reported Infections:
Medium to high
Distribution Potential:
Medium
Damage Potential:
Low
Static file:
Yes
File size:
17.424 Bytes
MD5 checksum:
6f49434d7e4532520372a4721a7a9aec
VDF version:
6.24.00.29
General
Method of propagation:
• Email
Aliases:
• Symantec: W32.Netsky.D@mm
• Mcafee: W32/Netsky.d@MM
• Kaspersky: Email-Worm.Win32.NetSky.d
• TrendMicro: WORM_NETSKY.DAM
• F-Secure: W32/Netsky.D@mm non-working
• Sophos: W32/NetskyD-Dam
• Grisoft: I-Worm/Netsky
• VirusBuster: I-Worm.Netsky.D3
• Eset: Win32/Netsky.D
• Bitdefender: Win32.Netsky.D@mm
Platforms / OS:
• Windows 95
• Windows 98
• Windows 98 SE
• Windows 2000
• Windows XP
Side effects:
• Uses its own Email engine
• Lowers security settings
• Registry modification
Files
It copies itself to the following location:
•
%WINDIR%
\winlogon.exe
Registry
The following registry key is added in order to run the process after reboot:
– HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
• "ICQ Net"=
%WINDIR%
\winlogon.exe -stealth"
The values of the following registry keys are removed:
– HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
• DELETE ME
• Explorer
• KasperskyAv
• msgsvr32
• Sentry
• service
• system.
• Taskmon
• Windows Services Host
– HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
• au.exe
• d3dupdate.exe
• Explorer
• KasperskyAv
• OLE
• Taskmon
• Windows Services Host
The following registry keys including all values and subkeys are removed:
• HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32
• HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\PINF
• HKLM\System\CurrentControlSet\Services\WksPatch
Email
It contains an integrated SMTP engine in order to send emails. A direct connection with the destination server will be established. The characteristics are described in the following:
From:
The sender address is spoofed.
To:
– Email addresses found in specific files on the system.
Subject:
One of the following:
• Re: Approved; Re: Details; Re: Document; Re: Excel file; Re: Hello;
Re: Here; Re: Here is the document; Re: Hi; Re: My details; Re: Re:
Document; Re: Re: Message; Re: Re: Re: Your document; Re: Re: Thanks!;
Re: Thanks!; Re: Word file; Re: Your archive; Re: Your bill; Re: Your
details; Re: Your document; Re: Your letter; Re: Your music; Re: Your
picture; Re: Your product; Re: Your software; Re: Your text; Re: Your
website
Body:
The body of the email is one of the lines:
• Your file is attached.
• Please read the attached file.
• Please have a look at the attached file.
• See the attached file for details.
• Here is the file.
• Your document is attached.
Attachment:
The filename of the attachment is one of the following:
• all_document.pif; application.pif; document.pif; document_4351.pif;
document_excel.pif; document_full.pif; document_word.pif;
message_details.pif; message_part2.pif; mp3music.pif; my_details.pif;
your_archive.pif; your_bill.pif; your_details.pif; your_document.pif;
your_file.pif; your_letter.pif; your_picture.pif; your_product.pif;
your_text.pif; your_website.pif; yours.pif
The attachment is a copy of the malware itself.
The email looks like the following:
Mailing
Search addresses:
It searches the following files for email addresses:
• .adb; .asp; .cgi; .dbx; .dhtm; .doc; .eml; .htm; .html; .msg; .oft;
.php; .pl; .rtf; .sht; .shtm; .tbb; .txt; .uin; .vbs; .wab
Avoid addresses:
It does not send emails to addresses containing one of the following strings:
• abuse; antivi; aspersky; avp; cafee; fbi; f-pro; f-secur; icrosoft;
itdefender; messagelabs; orman; orton; skynet; spam; ymantec
Resolving server names:
If the request using the standard DNS fails it continues with the following
It has the ability to contact the following DNS servers:
• 145.253.2.171; 151.189.13.35; 193.141.40.42; 193.189.244.205;
193.193.144.12; 193.193.158.10; 194.25.2.129; 194.25.2.130;
194.25.2.131; 194.25.2.132; 194.25.2.133; 194.25.2.134;
195.185.185.195; 195.20.224.234; 212.185.252.136; 212.185.252.73;
212.185.253.70; 212.44.160.8; 212.7.128.162; 212.7.128.165;
213.191.74.19; 217.5.97.137; 62.155.255.16
Miscellaneous
Mutex:
It creates the following Mutex:
• [SkyNet.cz]SystemsMutex
String:
Furthermore it contains the following string:
• "be aware! Skynet.cz - -->AntiHacker Crew<--"
See a brief description
here
.
Inserted by Irina Boldea on Tue, 30 Aug 2005 10:19 (GMT+1)
Updated by Irina Boldea on Thu, 01 Sep 2005 13:47 (GMT+1)
« Back
Print this page
Latest News
Avira survey shows 1 in 3 people think all websites pose security threat
Avira warns of Windows vulnerability
HEUR/HTML.Malware
TR/Crypt.XPACK.Gen2
W32/Sality.Y
Java/Agent.M.1
HTML/Crypted.Gen
TR/Renos.AB.4
TR/Renos.AT
TR/Fakealert.MA.591
TR/Agent.321536
TR/Agent2.loa
Download here
© 2010 Avira Soft SRL
Privacy
|
Site terms
|
Copyright
|
Site map