Netsky.p: Prevention and cure

Topics

netsky.p, netsky, virus

The latest variation of the Netsky Internet worm automatically executes without the user having to open the attached file.

Netsky.p (w32.netsky.p@cnet.com) takes advantage of the Incorrect MIME header in Internet Explorer, the app that renders HTML e-mail for Microsoft Outlook. A patch to correct this IE flaw has been available from Microsoft since 2001. Netsky.p also spreads via shared network files. This worm will attempt to delete Registry keys from infected computers. Netsky.p does not affect users of Linux, the Mac OS, or Unix. Because Netsky.p spreads via e-mail and could damage system files, this worm rates a 6 on the CNET/ZDNet Virus Meter.

How it works
Netsky.p arrives via e-mail using a spoofed e-mail address as the sender. The subject is taken from one of the following choices:

Stolen document
Re:Hello
Mail Delivery
Private document
Re:Notify
Re:document
Re:Extended Mail System
Re:Proctected Mail System
Re:Question
Private document
Postcard

The body text is taken from the following list:

I found this document about you.
I have attached it to this mail.
Waiting for authentification.
Please confirm!
Protected message is available
Do not visit this illegal websites!
Here is my phone number.
I cannot believe that.
Your file is attached.
For further details see that attachment.
Congratulations!, your best friend.
Greetings from france, your friend.
If the message will not displayed automatically, follow the link to read the delivered message.
Received message is available at: (a bogus URL)

The attached file is a zip file. Netsky.p also searches shared file directories that use the following words:

shared files
kazaa
mule
donkey
morpheus
lime
bear
icq
shar
upload
http
htdocs
ftp
download
my shared folder

According to McAfee, once executed, Netspky.p copes itself as FVProtect.exe and adds the following files to the Windows file folder:

userconfig9x.dll (26,624)
base64.tmp (UUEncoded worm)
zip1.tmp (a worm zip archive)
zip2.tmp (a worm zip archive)
zip3.tmp (a worm zip archive)
zipped.tmp (a worm zip archive)

The worm sends copies of itself to e-mail addresses found on the infected PC.

Netsky.p also creates the following Registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Norton Antivirus AV" =
[[Windows folder]]\FVProtect.exe

Netsky.p deletes the following Registry keys if present:

HKEY_LOCAL_MACHINE\System\CurrentControlSet Services\WksPatch
HKEY_CURRENT_USER\Software\Microsoft\Windows CurrentVersion\Explorer\PINF
HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87- 00AA005127ED}InProcServer32

Netsky.p uses an Internet Explorer vulnerability from 2001, MS01-020, to execute automatically; however, automatic execution should affect only users still running unpatched versions of Internet Explorer 5.01 or 5.5.

Prevention
Users of Internet Explorer 5.01 or 5.5 are urged to patch their software if they haven't done so already.

Removal
A few antivirus software companies have updated their signature files to include this worm. This will stop the infection upon contact and in some cases will remove an active infection from your system. For more information, see Computer Associates, F-Secure, McAfee, Sophos, Symantec, and Trend Micro.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

“@zdnetaustralia: Is Windows Phone really the third challenger to Android and iOS? http://t.co/Tr7ASra0 ”. It's different but fast and good

Can HP bounce back? http://t.co/TSlWjmrA

Thanks for the response Luke, Given that the quotes are accurate, then the person in charge of the Vic Health App needs to find another j...

8 minutes ago by butterflyeffecs on Android fragmentation steers Vic Health

Social business in Australia http://t.co/aBuXFy40 . Australian businesses still laging behind with social business. Time to catch up!

Can Windows Phone bring a new challenge? #WindowsPhone http://t.co/m82nU7hK

Nice analogy. Another factor is whether you can find 50 people with powerful enough weapons. Minassian's argument is essentially that the...

18 minutes ago by Mukimu on National Botnet Network coming: Earthwave

RT @digitaltasmania: @ZDNetAustralia #NBN's Tassie upgrade to cost $1.3m http://t.co/1nTbLUJv -Countdown begins for 1st Oppn. MP to misconstrue per unit cost

@ZDNetAustralia #NBN's Tassie upgrade to cost $1.3m http://t.co/1nTbLUJv -Countdown begins for 1st Oppn. MP to misconstrue per unit cost

RT @mosfreshmedia: Start-up accelerator targets cleantech 'Atlassians, BigCommerce' via @zdnetaustralia http://t.co/oho3oQSK @atpinnovations @hamishhawthorn

Can #HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development (R&D) and generally get... http://t.co/dlgAhwxb

Can HP bounce back? http://t.co/qLlHB5FV

It's nice to see Tas finally get some decent internet connectivity, for too long Tas has been stooged on decent internet connectivity but...

39 minutes ago by Jingles on NBN's Tassie upgrade to cost $1.3 million

Cloud inefficiency - Bad habits are hard to break: Cloud can save you a lot of money - if you use it effectively... http://t.co/oVoNx2na

by http://t.co/vmlLt4bh: Can HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development ... http://t.co/EjWWU9O1

Can HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development (R&D) and generally get ... http://t.co/KDGewBVH

Can HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development (R&D) and generally get ... http://t.co/y2ajlh9V

Three tips for businesses to support connected customers: While the connected home offers benefits to the consum... http://t.co/psgHJelD

#Agedcare 30 servers to 7: BUPA redoes virtualisation: Most IT teams spend 90 per cent of today making sure that... http://t.co/HmVXHRQ7

[plug] #NBN cost-benefit analyses are so 2011 http://t.co/2mRUKI8G @TurnbullMalcolm has forgotten his CBA; sh/would he still do one? #zdnet

Can HP bounce back? http://t.co/LlAUcyYP

Who is Luke Hartsuyker? He must be the Apprentice FUDster. As PaulPC has already said regional consumers want, deserve and are entitled...

1 hour ago by dickster on Regional review highlights NBN, mobile

Three tips for businesses to support connected customers http://t.co/W7Sr3RpD

by http://t.co/vmlLt4bh: Did RIM shelve plans to license BBM?: Research In Motion (RIM) had considered licensing ... http://t.co/z6VlO472

Did RIM shelve plans to license BBM? - ZDNet Australia http://t.co/j042NNOM

Did RIM shelve plans to license BBM? - ZDNet Australia http://t.co/qMNEifi1

Its good to see the NBN keeping up with the latest equipement & letting the people benefit from it. After all thats why it was a trial, ...

1 hour ago by fibretech on NBN's Tassie upgrade to cost $1.3 million

#Google TV will revolutionize television once viewers understand it http://t.co/Pmie5zEC http://t.co/2GN4qz9j http://t.co/j3wf6jEF

RT @zdnetaustralia: NBN Co will spend $1.3 million upgrading some 700 network terminating units in Tasmania. http://t.co/6GWYMcZQ

Did RIM shelve plans to license BBM?: Research In Motion (RIM) had considered licensing BlackBerry Messenger (BB... http://t.co/G13GBXl4

Did RIM shelve plans to license BBM? http://t.co/KKPZVPOr

Did RIM shelve plans to license BBM? http://t.co/1AutUH8l

Are college students dependent on technology? http://t.co/4p3v9PZ9 via @ZDNet

30 servers to 7: BUPA redoes virtualisation http://t.co/dOR009Te

Govt urges telcos to team up against NBN Co http://t.co/Sn7pMhew

NBN's Tassie upgrade to cost $1.3 million http://t.co/iDlBr20I

Govt urges telcos to team up against NBN Co: The Department of Broadband, Communications and the Di... http://t.co/YVVOyRWA #suretelecom

by http://t.co/vmlLt4bh: NBN's Tassie upgrade to cost $1.3 million: NBN Co will spend $1.3 million on replacing o... http://t.co/FwL9gNKF

NBN's Tassie upgrade to cost $1.3 million: NBN Co will spend $1.3 million on replacing outdated network technolo... http://t.co/sIP3aI5l

RT @zdnetaustralia: Google found itself embroiled in a vicious tax debate this week. Serves it right? http://t.co/Ga14Yg6x ^ST

NBN's Tassie upgrade to cost $1.3 million: NBN Co will spend $1.3 million on replacing outdated network technolo... http://t.co/JYdFJbxj

Shadow Minister for Regional Communications Luke Hartsuyker has got it wrong. Regional consumers want improved mobile services AND the NB...

2 hours ago by PaulPC on Regional review highlights NBN, mobile

Just remember that Google haven't broken any laws here, they're just doing what all their other multinational competitiors do; minimise t...

2 hours ago by Pachanga on Much ado about Google's tax

ルイヴィトン バッグ : http://www.lovebagjp.com/ Louis Vuitton bags, Louis Vuitton pretension nose about,Louis Vuitton daydre...

2 hours ago by bundLourb on Reservoir blogs: Fan fakes Tarantino diary

シャネル バッグ : http://www.bagssalejp.org/ Chanel trap,chanel shekels,gucci bags,direct purse,poor recent Louis Vuitton keep...

4 hours ago by bybrinkLync on Reservoir blogs: Fan fakes Tarantino diary

I guess but in both cases, dead body!

14 hours ago by Doubt on National Botnet Network coming: Earthwave

I think it's for the very reasons you mention in your first paragraph that there is no CBA. With the ideological differences and vested ...

15 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

Good points; but how do you establish consensus about the terms of reference of a cost-benefit analysis? What is to be included? How far ...

15 hours ago by Gwyntaglaw on NBN cost-benefit analyses are so 2011

I live in a small country town & have done since 2002. When I got to this town it had no mobile phone & no broadband. The only reason w...

16 hours ago by fibretech on Regional review highlights NBN, mobile

Hi there, just became alert to your blog through Google, and found that it is really informative. I am going to watch out for brussels. I...

16 hours ago by Uttedsips on Fujitsu Stylistic ST5011

Like most things in life, the devil is in the details. If a cost benefit analysis included a societal element, I'm certain nobody on eit...

16 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

The coalition has done nothing else but keep changing their view over the last 2 years. -first it was "there is nothing wrong with the ...

17 hours ago by djz on NBN cost-benefit analyses are so 2011

Use the force Luke... FFS

17 hours ago by Beta on Regional review highlights NBN, mobile

michael kors outlet http://www.michael-kors-discount.com/#5923

17 hours ago by michael kors bag on Best iPhone travel apps

Hey butterflyeffecs and lex, Sorry you're not fans of this piece. But you're dead right in that it is the thoughts and experience of a se...

17 hours ago by LHopewell on Android fragmentation steers Vic Health

teen cams
http://www.aloe-vera.cz handjob

17 hours ago by MyncWenry on Fusion-io ioDrive (80GB)

This story has been voted 12000 times in the last 24 hours!

20 hours ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar