Virus Characteristics
-- Update August 16th, 2004 --
The risk assessment of this threat has been lowered to Low-Profiled due to decreased prevalence.
--
-- Update March 8, 2004 1:40pm PDT --
The risk assessment of this threat was raised due to an increase in prevalence.
If you think that you may be infected with Netsky.j, and are unsure how to check your system, you may
download the Stinger tool
to scan your system and remove the virus if present. This is not required for McAfee users as McAfee products are capable of detecting and removing the virus with the latest update. (see the removal instructions below for more information).
Note:
Receiving an email alert stating that the virus came from your email address is not
an indication that you are infected as the virus often forges the from address.
|
This is a repackaged version of W32/Netsky.d@MM
.
This virus spreads via email. It sends itself to addresses found on the victim's machine. The virus also attempts to deactivate the W32/Mydoom.a@MM
and W32/Mydoom.b@MM
viruses.
Mail propagation
The virus may be received in an email message as follows:
From:
(forged address taken from infected system)
Subject:
Taken from the following list:
- Re: Hello
- Re: Hi
- Re: Thanks!
- Re: Document
- Re: Message
- Re: Here
- Re: Details
- Re: Your details
- Re: Approved
- Re: Your document
- Re: Your text
- Re: Excel file
- Re: Word file
- Re: My details
- Re: Your music
- Re: Your bill
- Re: Your letter
- Re: Document
- Re: Your website
- Re: Your product
- Re: Your document
- Re: Your software
- Re: Your archive
- Re: Your picture
- Re: Here is the document
Body:
Taken from the following list:
- Here is the file.
- Your file is attached.
- Your document is attached.
- Please read the attached file.
- Please have a look at the attached file.
- See the attached file for details.
Attachment:
filename taken from strings within worm, with a .PIF extension:
- yours.pif
- your_text.pif
- your_bill.pif
- mp3music.pif
- document.pif
- my_details.pif
- your_file.pif
- your_website.pif
- your_product.pif
- your_letter.pif
- your_archive.pif
- your_details.pif
- document_word.pif
- all_document.pif
- application.pif
- your_picture.pif
- document_excel.pif
- document_4351.pif
- document_full.pif
- message_part2.pif
- your_document.pif
- message_details.pif
The mailing component harvests address from the local system. Files with the following extensions are targeted:
- .adb
- .asp
- .cgi
- .dbx
- .dhtm
- .doc
- .eml
- .htm
- .oft
- .php
- .pl
- .rtf
- .sht
- .shtm
- .msg
- .tbb
- .txt
- .uin
- .vbs
- .wab
It does not send itself to addresses that contain one of the following strings:
- abuse
- fbi
- orton
- f-pro
- aspersky
- cafee
- orman
- itdefender
- f-secur
- avp
- skynet
- spam
- messagelabs
- ymantec
- antivi
- icrosoft
The virus sends itself via SMTP - constructing messages using its own SMTP engine. It queries the DNS server for the MX record and connects directly to the MTA of the targeted domain and sends the message.
System changes
The worm copies itself into %WinDir% (eg. C:\WINDOWS) folder using the filename WINLOGON.EXE.
- C:\WINNT\WINLOGON.EXE (22,016 bytes)
Note:
A valid file exists in the Windows System directory.
A Registry key is created to load the worm at system start.
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run
"ICQ Net" = %WinDir%\WINLOGON.EXE -stealth
Virus removal
The virus removes various Registry values. Some of these are associated with other viruses, trojans, and applications.
The following registry key values are deleted:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Run "au.exe"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Run "d3dupdate.exe"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Run "Explorer"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Run "KasperskyAv"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Run "OLE"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Run "Taskmon"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "DELETE ME"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "Explorer"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "KasperskyAv"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "msgsvr32"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "Sentry"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "service"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "system."
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "Taskmon"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\RunServices "system."
- HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32