This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Virus Removal Tool...

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…Since this piece of malware is reported to be -high- on the list (it is here, anyway: http://www.postini.com/stats/index.html ), the following is provided for those who contract this piece of vermin:

W32.Netsky@mm Removal Tool
(Several versions of Netsky have been released, likely more on the way. The downloaded removal tool will probably be updated as more variants appear. Check back for updates, same URL)
- http://www.sarc.com/avcenter/venc/data/w32…moval.tool.html

.
FYI…from the Internet Storm Center:

- http://isc.sans.org/diary.html?date=2004-03-23
"New Netsky Variant
Symantec moved the new Netsky variant to level 3. The netsky.p variant also uses a vulnerability in IE to execute E-mail attachments. This is a known flaw and has a patch available since 2001.
Reference - http://www.eweek.com/print_article/0,1761,a=122178,00.asp …"

(NOTE: The Symantec removal tool has been updated to include this variant - use the same URL posted above in this thread)

.
FYI…

- http://www.messagelabs.com/viruseye/info/netskyp.asp
"…MessageLabs is continuing to intercept high numbers of the W32/Netsky.P-mm, a mass-mailing email worm which contains its own SMTP engine and harvests email addresses from infected machines in order to spread. Since the worm first appeared four days ago, MessageLabs has intercepted a total of 3.8 million copies. The majority of emails containing the worm were caught during the past thirty-six hours, as the worm's mass-mailing function triggered on 24th March, 2004. The current infection ratio for W32/Netsky.P is 1 in 33.

Important: Please note that the emails sent contain spoofed disclaimers which randomly reference…anti-virus vendors in an attempt to lure users into a false sense of security…"

.
FYI…

- http://www.securitypipeline.com/news/showA…bleArticle=true
"…Netsky.q includes a file attachment that infects the target machine when opened, it doesn't necessarily need users to take that step to compromise a system. On machines unpatched against 2001's "Incorrect MIME Header Can Cause IE to Execute E-mail Attachment" vulnerability in IE 5.01 (without SP2) and 5.5, Netsky.q will automatically execute its payload if the recipient simply views or opens the HTML e-mail…"

.
FYI…from the Internet Storm Center:

- http://isc.sans.org/diary.html?date=2004-04-03
"W32.Netsky.Q@mm - According to Symantec's Security Response Website the W32.Netsky.Q@mm virus is set to perform a DoS next week. Here is an excerpt from Symantec's Website information:

'If the system date is April 8th, 2004 through April 11th, 2004 it will attempt to perform a Denial of Service (DoS) attack…This worm is taking advantage of unpatched systems to exploit the Incorrect MIME Header Can Cause IE to Execute E-mail Attachment ( http://www.microsoft.com/technet/security/…n/MS01-020.mspx )'

Symantec has a removal tool available at:
- http://www.sarc.com/avcenter/venc/data/w32…moval.tool.html

If you are not absolutely sure that your computer is free from the Netsky worm, you should download and run the removal tool on your computer…"

(More info here: http://www.trendmicro.com/vinfo/virusencyc…ETSKY.Q&VSect=T )

.
FYI…

- http://www.techweb.com/wire/story/TWB20040408S0008
April 8, 2004
"…Netsky.s, Netsky.t, and Netsky.u – which first appeared on the Internet this past weekend, on Monday, and on Wednesday, respectively – all share one characteristic that separates them from the previous 18 variations: they install a backdoor component that leaves open TCP port 6789. Backdoors are dangerous because they allow the original hacker, or other attackers, to scan for the open port, and when found, plant arbitrary code on the compromised machine, including key loggers to steal passwords or new variations of a worm, or turn the system into a spam-spewing engine…"

- http://isc.sans.org/port_details.php?port=6789

.