FYI…Since this piece of malware is reported to be -high- on the list (it is here, anyway: http://www.postini.com/stats/index.html ), the following is provided for those who contract this piece of vermin:
W32.Netsky@mm Removal Tool
(Several versions of Netsky have been released, likely more on the way. The downloaded removal tool will probably be updated as more variants appear. Check back for updates, same URL)
- http://www.sarc.com/avcenter/venc/data/w32…moval.tool.html
- http://www.messagelabs.com/viruseye/info/netskyp.asp
"…MessageLabs is continuing to intercept high numbers of the W32/Netsky.P-mm, a mass-mailing email worm which contains its own SMTP engine and harvests email addresses from infected machines in order to spread. Since the worm first appeared four days ago, MessageLabs has intercepted a total of 3.8 million copies. The majority of emails containing the worm were caught during the past thirty-six hours, as the worm's mass-mailing function triggered on 24th March, 2004. The current infection ratio for W32/Netsky.P is 1 in 33.
Important: Please note that the emails sent contain spoofed disclaimers which randomly reference…anti-virus vendors in an attempt to lure users into a false sense of security…"
- http://www.securitypipeline.com/news/showA…bleArticle=true
"…Netsky.q includes a file attachment that infects the target machine when opened, it doesn't necessarily need users to take that step to compromise a system. On machines unpatched against 2001's "Incorrect MIME Header Can Cause IE to Execute E-mail Attachment" vulnerability in IE 5.01 (without SP2) and 5.5, Netsky.q will automatically execute its payload if the recipient simply views or opens the HTML e-mail…"
- http://isc.sans.org/diary.html?date=2004-04-03
"W32.Netsky.Q@mm - According to Symantec's Security Response Website the W32.Netsky.Q@mm virus is set to perform a DoS next week. Here is an excerpt from Symantec's Website information:
'If the system date is April 8th, 2004 through April 11th, 2004 it will attempt to perform a Denial of Service (DoS) attack…This worm is taking advantage of unpatched systems to exploit the Incorrect MIME Header Can Cause IE to Execute E-mail Attachment ( http://www.microsoft.com/technet/security/…n/MS01-020.mspx )'
- http://www.techweb.com/wire/story/TWB20040408S0008
April 8, 2004
"…Netsky.s, Netsky.t, and Netsky.u – which first appeared on the Internet this past weekend, on Monday, and on Wednesday, respectively – all share one characteristic that separates them from the previous 18 variations: they install a backdoor component that leaves open TCP port 6789. Backdoors are dangerous because they allow the original hacker, or other attackers, to scan for the open port, and when found, plant arbitrary code on the compromised machine, including key loggers to steal passwords or new variations of a worm, or turn the system into a spam-spewing engine…"