Content

W32/Netsky.n@MM

Type
Virus
SubType
E-mail worm
Discovery Date
03/15/2004
Length
Varies
Minimum DAT
4339 (03/17/2004)
Updated DAT
4994 (03/28/2007)
Minimum Engine
5.1.00
Description Added
03/15/2004
Description Modified
03/17/2004 5:03 PM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This mass-mailing worm is based on the source code for W32/Netsky.  Analysis is ongoing.

Mail propagation
The virus may be received in an email message as follows:

From: (forged address taken from infected system)
Subject: (Taken from the following list)

Part 1 (one of the following)

  • Re:
  • Re: Re:

Part 2 (one of the following)

  • my
  • your
  • (blank)

Part 3 (one of the following)

  • read it immediately
  • important
  • improved
  • patched
  • corrected
  • approved
  • thanks!
  • hello
  • hi
  • here
  • document_all
  • text
  • message
  • data
  • excel document
  • word document
  • bill
  • screensaver
  • application
  • website
  • product
  • letter
  • information
  • details
  • file
  • document
  • important
  • approved

Body: (Taken from the following list)

  • Your details.
  • Your document.
  • I have received your document. The corrected document is attached.
  • I have attached your document.
  • Your document is attached to this mail.
  • Authentication required.
  • Requested file.
  • See the file.
  • Please read the important document.
  • Please confirm the document.
  • Your file is attached.
  • Please read the document.
  • Your document is attached.
  • Please read the attached file.
  • Please see the attached file for details.

Followed by:

  • --------------------------------------------
    (attachment_name) : No virus found
    Powered by the new Norton OnlineScan
    Get protected: www.symantec.com

Attachment: (Taken from the following list, followed by .ZIP, .PIF, .EXE, .SCR)

  • document_all_%s
  • text_%s
  • message_%s
  • data_%s
  • excel document_%s
  • word document_%s
  • bill_%s
  • screensaver_%s
  • application_%s
  • website_%s
  • product_%s
  • letter_%s
  • information_%s
  • details_%s
  • file_%s
  • document_%s
  • important_%s
  • approved_%s

(Where %s will be replaced with the portion of the recipient's email address before the @ - e.g. if the email address in the To: field is user@mail.com, %s would be replaced with the string "user". The _ and %s may be omitted)

The mailing component harvests address from the local system.  Files with the following extensions are targeted:

  • .xml
  • .wsh
  • .jsp
  • .msg
  • .oft
  • .sht
  • .dbx
  • .tbb
  • .adb
  • .dhtm
  • .cgi
  • .shtm
  • .uin
  • .rtf
  • .vbs
  • .doc
  • .wab
  • .asp
  • .php
  • .txt
  • .eml
  • .html
  • .htm
  • .pl

The virus sends itself via SMTP - constructing messages using its own SMTP engine. It queries the DNS server for the MX record and connects directly to the MTA of the targeted domain and sends the message

Symptoms

The worm copies itself into %WinDir% (eg. C:\WINDOWS) folder using the filename VisualGuard.exe

  • C:\WINNT\VisualGuard.exe (33,792 bytes)

A Registry key is created to load the worm at system start.

  •  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
    CurrentVersion\Run
    "NetDy" = %WinDir%\VisualGuard.exe  

  • Unexpected network traffic
  • The following files are created in the WINDOWS (%WinDir%) directory:
    • base64.tmp - base64 encoded version of the executable
    • VisualGuard.exe - copy of the worm executable
    • zip1.tmp - base64 encoded version of worm in zip archive
    • zip2.tmp - base64 encoded version of worm in zip archive
    • zip3.tmp - base64 encoded version of worm in zip archive
    • zip4.tmp - base64 encoded version of worm in zip archive
    • zip5.tmp - base64 encoded version of worm in zip archive
    • zip6.tmp - base64 encoded version of worm in zip archive
    • zipped.tmp - worm in zip archive

    Virus removal
    The virus removes various Registry values.  Some of these are associated with other viruses, trojans, and applications.

    The following registry key values are deleted:

    • HKEY_CURRENT_USER\Software\Microsoft\Windows\
      CurrentVersion\Run "au.exe"
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\
      CurrentVersion\Run "d3dupdate.exe"
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\
      CurrentVersion\Run "Explorer"
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\
      CurrentVersion\Run "OLE"
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\
      CurrentVersion\Run "Taskmon"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "DELETE ME"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "Explorer"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "msgsvr32"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "Sentry"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "service"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "system."
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "Taskmon"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\RunServices "system."
    • HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32
  • Method of Infection

    This worm spreads by email, constructing messages using its own SMTP engine

    Removal

    All Users:
    Use current engine and DAT files for detection and removal.

    Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

    Additional Windows ME/XP removal considerations

    Variants

    Variants

      N/A

    All Information

    Overview -

    This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

    Characteristics

    Characteristics -

    This mass-mailing worm is based on the source code for W32/Netsky.  Analysis is ongoing.

    Mail propagation
    The virus may be received in an email message as follows:

    From: (forged address taken from infected system)
    Subject: (Taken from the following list)

    Part 1 (one of the following)

    • Re:
    • Re: Re:

    Part 2 (one of the following)

    • my
    • your
    • (blank)

    Part 3 (one of the following)

    • read it immediately
    • important
    • improved
    • patched
    • corrected
    • approved
    • thanks!
    • hello
    • hi
    • here
    • document_all
    • text
    • message
    • data
    • excel document
    • word document
    • bill
    • screensaver
    • application
    • website
    • product
    • letter
    • information
    • details
    • file
    • document
    • important
    • approved

    Body: (Taken from the following list)

    • Your details.
    • Your document.
    • I have received your document. The corrected document is attached.
    • I have attached your document.
    • Your document is attached to this mail.
    • Authentication required.
    • Requested file.
    • See the file.
    • Please read the important document.
    • Please confirm the document.
    • Your file is attached.
    • Please read the document.
    • Your document is attached.
    • Please read the attached file.
    • Please see the attached file for details.

    Followed by:

    • --------------------------------------------
      (attachment_name) : No virus found
      Powered by the new Norton OnlineScan
      Get protected: www.symantec.com

    Attachment: (Taken from the following list, followed by .ZIP, .PIF, .EXE, .SCR)

    • document_all_%s
    • text_%s
    • message_%s
    • data_%s
    • excel document_%s
    • word document_%s
    • bill_%s
    • screensaver_%s
    • application_%s
    • website_%s
    • product_%s
    • letter_%s
    • information_%s
    • details_%s
    • file_%s
    • document_%s
    • important_%s
    • approved_%s

    (Where %s will be replaced with the portion of the recipient's email address before the @ - e.g. if the email address in the To: field is user@mail.com, %s would be replaced with the string "user". The _ and %s may be omitted)

    The mailing component harvests address from the local system.  Files with the following extensions are targeted:

    • .xml
    • .wsh
    • .jsp
    • .msg
    • .oft
    • .sht
    • .dbx
    • .tbb
    • .adb
    • .dhtm
    • .cgi
    • .shtm
    • .uin
    • .rtf
    • .vbs
    • .doc
    • .wab
    • .asp
    • .php
    • .txt
    • .eml
    • .html
    • .htm
    • .pl

    The virus sends itself via SMTP - constructing messages using its own SMTP engine. It queries the DNS server for the MX record and connects directly to the MTA of the targeted domain and sends the message

    Symptoms

    Symptoms -

    The worm copies itself into %WinDir% (eg. C:\WINDOWS) folder using the filename VisualGuard.exe

    • C:\WINNT\VisualGuard.exe (33,792 bytes)

    A Registry key is created to load the worm at system start.

    •  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run
      "NetDy" = %WinDir%\VisualGuard.exe  

  • Unexpected network traffic
  • The following files are created in the WINDOWS (%WinDir%) directory:
    • base64.tmp - base64 encoded version of the executable
    • VisualGuard.exe - copy of the worm executable
    • zip1.tmp - base64 encoded version of worm in zip archive
    • zip2.tmp - base64 encoded version of worm in zip archive
    • zip3.tmp - base64 encoded version of worm in zip archive
    • zip4.tmp - base64 encoded version of worm in zip archive
    • zip5.tmp - base64 encoded version of worm in zip archive
    • zip6.tmp - base64 encoded version of worm in zip archive
    • zipped.tmp - worm in zip archive

    Virus removal
    The virus removes various Registry values.  Some of these are associated with other viruses, trojans, and applications.

    The following registry key values are deleted:

    • HKEY_CURRENT_USER\Software\Microsoft\Windows\
      CurrentVersion\Run "au.exe"
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\
      CurrentVersion\Run "d3dupdate.exe"
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\
      CurrentVersion\Run "Explorer"
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\
      CurrentVersion\Run "OLE"
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\
      CurrentVersion\Run "Taskmon"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "DELETE ME"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "Explorer"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "msgsvr32"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "Sentry"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "service"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "system."
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\Run "Taskmon"
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
      CurrentVersion\RunServices "system."
    • HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32
  • Method of Infection

    Method of Infection -

    This worm spreads by email, constructing messages using its own SMTP engine

    Removal -

    Removal -

    All Users:
    Use current engine and DAT files for detection and removal.

    Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

    Additional Windows ME/XP removal considerations

    Variants

    Variants -

      N/A