Disinfection instructions can be found here:
ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.txt
System administrators who are using F-Secure Policy Manager,
can distribute the tool as a JAR package automatically to all
workstations.
System administrators can download the JAR version from:
http://www.europe.f-secure.com/tools/f-netsky.jar
ftp://ftp.europe.f-secure.com/anti-virus/tools/f-netsky.jar
The worm's file is a packed PE executable of length 19432 bytes.
Some of the worm's text strings are scrambled.
Installation to system
Upon execution NetSky.V copies itself as EastAV.exe file to
Windows folder and adds a startup key for this file into System
Registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KasperskyAVEng" = "%WinDir%\KasperskyAVEng.exe"
where %WinDir% represents Windows folder name.
Spreading in e-mail
Netsky.V arrives in infected emails but does not use an
attachment. It sends HTML emails which exploit vulnerability
known as Microsoft Internet Explorer XML Page Object Type
Validation Vulnerability (MS03-040) that downloads a HTML page
from an infected host. This HTML page then uses another
vulnerbility, Internet Explorer Object Data Remote Execution
(MS03-032), that attempts to download the binary part of the worm
using command line ftp client, and executes it.
Further information about these vulnerabilities, including a fix, is
available from Microsoft:
http://www.microsoft.com/technet/security/bulletin/ms03-032.mspx
http://www.microsoft.com/technet/security/bulletin/ms03-040.mspx
The email harvesting functionality is identical to the variant NetSky.U.
The messages will have any of the following format:
Subject: Mail Delivery Sytem failure
Body: The processing of this message can take a few minutes...
Subject: Mail delivery failed
Body: Converting message. Please wait...
Subject: Server Status failure
Body: Please wait while loading failed message...
Subject: Gateway Status failure
Body: Please wait while converting the message...
Payload
Netsky.V has a payload. It performs a DoS (Denial of Service)
attack on the following websites from 22nd to 29th of April 2004:
www.cracks.am
www.emule.de
www.kazaa.com
www.freemule.net
www.keygen.us
Detection of NetSky.V worm was published on April 15th, 2004 in
the following F-Secure Anti-Virus updates:
[FSAV_Database_Version]
Version=2004-04-15_02
Technical Details:
Katrin Tocheva, Ero Carrera, Sami Rautiainen, Alexey Podrezov, April 15th, 2004;
Description Updated:
Alexey Podrezov, April 28th, 2004;
F-Secure Corporation