Second NetSky worm on the loose

The second version of a two-day-old virus, NetSky, has started spreading more successfully than its parent, antivirus researchers said on Wednesday.

The new variant, NetSky.b, uses e-mail to sends copies of itself to potential victims--people with computers running the Microsoft Windows operating system. It also stores copies of itself in shared directories, apparently to facilitate its propagation via file-sharing networks.

"The author, it seems, has done something to improve the virus's spread," said Alfred Huger, the senior director of engineering for security firm Symantec.

Symantec rated the virus a three on its five-point scale, while rival Network Associates gave the program a "medium" threat rating. The worm appears only to want to spread itself and not to launch an attack.

E-mail messages carrying NetSky.b come with almost 50 different subject lines and body text, from "I have your password!" to the succinct "OK." It carries a file attachment with a double extension, which can arrive in a variety of formats, including a ZIP archive. The virus sends e-mail on its own and also copies itself to shared directories and so can spread through Kazaa, BearShare, LimeWire and other peer-to-peer networks.

"On the mailing side, this is one of the more successful viruses," said Craig Schmugar, a virus research manager with Network Associates' antivirus and vulnerability emergency response team.

Schmugar said its success is somewhat puzzling because the social engineering--the way the virus's author words the e-mail that carries the program--is so minimalist.

However, the virus may not be wordy, but its e-mail messages do have a significant number of variations, Chris Belthoff, a senior security analyst at Lynnfield, Massachusetts-based Sophos, noted in a statement.

"Netsky-B is tricky to identify because of the wide variety of subject lines and message texts, but blocking all files with double extensions is an easy way to avoid infection," he said. The use of double extensions--such as .jpeg.exe--is a common trick among virus writers because Microsoft Outlook will remove the final extension hiding the true file type.

Of the two viruses that started spreading this week--NetSky.b and Bagle.b--the latter is more serious, according to Symantec's Huger.

"The Bagle virus's spread was about the same but its payload is much more dangerous," he said.

Advertisement

Talkback 0 comments


Latest Videos

ZDNet's CIO Vision Series

Department of Defence | Greg Farr, CIO (part two)

In the second part of his interview, Defence CIO Greg Farr talks about outsourcing, the skills crisis and reveals his most urgent IT priority.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Angus Kidman I'm a celebrity, don't back me up
    Celebrity comes with its perks — free alcohol, better-looking partners, lots of holiday time — and disadvantages — constant media intrusions, being forced to appear in films with Eddie Murphy for the long-term good of your career, and having to do mindless radio interviews with angry men who've been awake since 4am.
  • Array Lies, damned lies and telco stupidity
    Earlier this month, Telstra put out a press release trumpeting that it's come up with a new phone coaching service to help people who are "bamboozled" by their mobiles. Another excellent example of wrongheaded thinking from the mobile industry.
  • Array Dear carriers: More walking, less talking
    Sometimes, a well-placed and well-timed letter can make all the difference. Other times, it can make no difference at all — and even hurt your case. This week's missive by the Competitive Carriers' Coalition, I would suggest, falls into the latter category.
  • More blogs »

Tags

Back to top

Featured