Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

WORM_NETSKY.C

BugsAlert Home > WORM_NETSKY.C
 
 

This new NETSKY variant spreads via email using its own SMTP (Simple Mail Transfer Protocol) engine. It also drops several copies of itself in folders that have the string "shar" in their names and are located under the Windows directory. It drops copies with enticing file names and may successfully propagate via folders shared on various networks.

The email message it sends out has varying details. Below are screenshots of some of its email messages:

This is a sample email that the worm sends out.

This box displays a sample email that the worm sends out.

This box displays a sample email that the worm sends out.

If the current system date is February 26, 2004 and the time is between 6 and 9 AM, this malware generates beeping sounds.

Additionally, this worm disables other malware. It deletes the registry entries used by certain malware to automatically execute at system startup.

This memory-resident malware runs on Windows 95, 98, ME, NT, 2000, and XP.




Original Source: http://feeds.trendmicro.com/~r/MalwareTop10/~3/207190030/default5.asp

Learn more about WORM_NETSKY.C
 
Tags: worm netsky.c

Related Items

      CVE-2008-2035 (Xoops, xoops cube, backpack, bmsurvey, newbb_fileup, news_fileup, popnupblog)

      Fastpublish CMS designconfig.php File Inclusion

      CVE-2008-3559 (KAPhotoservice)

      Skype Releases Security Bulletin to Address CrossZone Scripting Vulnerability

      CVE-2008-3514 (VirtualCenter)

      Vuln: Yukihiro Matsumoto Ruby CGI.RB Library Remote Denial Of Service Vulnerability

      Phorum BBcode Nested "img" Tags Script Insertion

 

Pixel