Google
Web pcflank.com
PC Flank Logo
Make sure
you're protected
on all sides
 Test Your System
 Ask the experts
 Community
 Security Center

 

Tip of the day
To avoid rust and bad connections, do not touch bare computer wires or connectors with wet or sweaty hands.

Security News

Another Internet cloggier under way

February 27, 2004

Another mass mailing worm, Netsky, appears on the Net. MessageLabs, an e-mail management company, claims to have stopped more than 1.3 million e-mail since the virus started spreading, which beats MyDoom spreading rate by about 10 times. The infection rate is believed to be increasing rapidly.

As other worms appeared this year, Netsky does require the user to open the attachment with the e-mail. "These days it's less to do with technology, with the code of the virus, and more to do with social engineering," says David Banes of MessageLabs.

The worm appears in the Inbox using a spoofed "from" address and a subject line chosen from one of the following: hi, hello, read it immediately, something for you, warning, information, stolen, fake, unknown. The body of the e-mail contains a variety of messages, and the attachment will normally have a double-file name or be a zip file. When the file is opened it displays a message "The file could not be opened!" before the virus activates.

After activation, Netsky scans the infected computer hard and shared drives for e-mail addresses and then uses its own SMTP engine to mail itself to those addresses. The worm also searches for shared folders and copies itself to those folders using a variety of file names, masquerading itself under various names as tools, patches, cracks, screen savers and porno pictures.

Like Nachi, Netsky attempts to clean the MyDoom virus by closing the backdoors open by that virus and removing it from the system. Netsky also contains several lines of text that might explain why it attempts to eliminate MyDoom:

<-<- we are the skynet - you can't hide yourself! -
we kill malware writers (they have no chance!)
- [LaMeRz-->]MyDoom.F is a thief of our idea!
- -< SkyNet AV vs. Malware >- ->->

Security companies estimate the economic damage done by Netsky worldwide to be at least US$3.12 billion. This was calculated "on the basis of helpdesk support costs, overtime payments, contingency outsourcing, loss of business, bandwidth clogging, productivity erosion, management time reallocation, cost of recovery, and software upgrades".

Despite requiring the computer user to actively run an attachment, Netsky seems to be spreading fast, with anti-virus vendors have already rated is as severe, which means that the users must take extreme care using email and opening suspicious attachments.

  Discuss this article on the Forum

 
 
Start Page
Make "PC Flank" your   
Start Page!   
Make

 
In the Spotlight
» One man's job

» Outpost Firewall Pro Review

   
 

 
Sponsored links


   
 
Related Links
» Check Point
acquires Zone Labs
for $205 million


» ZoneLabs
will not fix
a vulnerability in
free version of
Zone Alarm firewall.


   
 

 
   
Outpost Firewall PRO 3.0 - complete protection on the Internet!

Secure Internet surfing with Oupost personal firewall with antispyware and free firewall available for download at www.agnitum.com.
 
Privacy Policy
    Advertiser Info
Site Map
    Contact Us

 
 
© 2006 PC Flank Ltd. All rights reserved.