Summary
Email-Worm:W32/Netsky.P mass-mails itself to new victims using both email and by copying itself across local networks (LAN) and Peer-to-Peer (P2P) networks, as well as FTP and HTTP folders.
Removal
Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.
A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:
- Check for the latest database updatesFirst, check if your F-Secure security program is using the latest updates, then try scanning the file again.
- Submit a sampleAfter checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.
- Exclude a file from further scanningIf you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.Note: You need administrative rights to change the settings.
Technical Details
Installation
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Norton Antivirus AV" = "%WinDir%\fvprotect.exe"
- zipped.tmp
- base64.tmp
- zip1.tmp
- zip2.tmp
- zip3.tmp
- document.txt [lots spaces].exe
- data.rtf [lots spaces].scr
- details.txt [lots spaces].pif
Activity
Registry Changes
- [HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32]
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\PINF]
- [HKLM\System\CurrentControlSet\Services\WksPatch]
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] system. Video
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] system. msgsvr32 winupd.exe direct.exe jijbl Video service DELETE ME Taskmon Explorer
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] OLE Sentry Taskmon Windows Services Host Explorer gouday.exe au.exe direct.exe d3dupdate.exe rate.exe sysmon.exe srate.exe ssate.exe winupd.exe
Propagation (email)
- .pl
- .htm
- .html
- .eml
- .txt
- .php
- .asp
- .wab
- .doc
- .vbs
- .rtf
- .uin
- .shtm
- .cgi
- .dhtm
- .adb
- .tbb
- .dbx
- .sht
- .oft
- .msg
- .jsp
- .wsh
- .xml
- @microsof
- @antivi
- @symantec
- @spam
- @avp
- @f-secur
- @bitdefender
- @norman
- @mcafee
- @kaspersky
- @f-pro
- @norton
- @fbi
- abuse@
- @messagel
- @skynet
- @pandasof
- @freeav
- @sophos
- ntivir
- @viruslis
- noreply@
- spam@
- reports@
- Re: Hi
- Re: Hello
- Please confirm!
- Please answer quickly!
- detail3.
- document_all02c.
- summary2004.
- Re: Request
- details05.
- data02.
- all_in_all.
- Shocking document
- You cannot do that!
- document05.
- your_document.
- document_with_notice.
- hi
- hello
- document05.
- game_xxo.
- websites03.
- Fwd: Warning again
- Notice again
- abuselist.
- abuses.
- websites01.
- Re: List
- Re: Question
- my_list01.
- my_numbers.
- archive.
- Spamed?
- Spam
- websitelist01.
- list_ed.
- abuse_list.
- 0i09u5rug08r89589gjrg
- id04009.
- id43342.
- id09509.
- important.
- details.
- message.
- Re: A!p$ghsa
- Important m$6h?3p
- important.
- details03.
- document07.
- Do you?
- Does it matter?
- text01.
- details.
- d4334938.
- News
- Information
- news01.
- info02.
- report01.
- I love you!
- I cannot forget you!
- letter43.
- story.
- photo.
- Re: Proof of concept
- Re: Developement
- document09.
- part_01.
- doc_word3.
- Re: Message
- Re: Error in document
- attach.
- document.
- message.
- Subject:
- Re: Free porn
- Re: Sex pictures
- www.freeporn4all.
- www.myx4free.
- Re: Submit a Virus Sample
- Re: Virus Sample
- signature.
- datfiles.
- Re: Old times
- Re: Old photos
- Greetings from france, your friend.
- old_photos.
- letter.
- Postcard
- Your day
- Best wishes, your friend. Congratulations!, your best friend.
- postcard.
- letter.
- Re: Sample
- Re: Question
- I have corrected your document.
- I have attached the sample.
- sample01.
- doc01.
- word_doc.
- document04.
- Thank you!
- Congratulations!
- Your bill is attached to this mail. You were registered to the pay system. For more details see the attachment.
- bill.
- list.
- confirm.
- details.
- Illegal Website
- Internet Provider Abuse
- I noticed that you have visited illegal websites. See the name in the list!
- You have visited illegal websites. I have a big list of the websites you surfed.
- list.
- abuselist.
- judge.
- readme.
- details.
- Mail Account
- Administrator
- Your mail account is expired. See the details to reactivate it.
- Your mail account has been closed. For further details see the document.
- account.
- readme.
- details.
- Re: Hi
- Re: Its me
- The file is protected with the password ghj001.
- I have attached your file. Your password is jkl44563.
- document.
- document43.
- priv.
- letter32.
- data20.
- mails9.
- your_doc.
- my_details.
- Private document
- Stolen document
- I found this document about you.
- I cannot believe that.
- document342.
- your_document.
- about_you.
- Hello
- Hi
- Try this game ;-)
- I hope the patch works.
- game.
- patch3425.
- application.
- software.
- Mail Delivery (failure)
- Error
- Binary message is available.
- Message has been sent as a binary attachment.
- message.
- msg.
- data.
- letter.
- email.
- Re: Is that your document?
- Is that your password?
- Can you confirm it?
- I have attached it to this mail.
- document.
- pwd02.
- document01.
- part6.
- private_01.
- Re: Approved document
- Re: Your document
- Please read the attached file.
- Your document is attached.
- file.
- your_document.
- about_you.
- document04.
- msg.
- all_doc01.
- document.
- approved.
- improved.
- corrected.
- Protected Mail System
- Mail Authentication
- Encrypted message is available.
- Protected message is attached.
- pgp_sess01.
- encrypted_msg01.
- document.
- message.
- msg.
- Re: Mail Authentification
- Re: Delivery Protection
- Re: Secure delivery
- Re: Protected Mail Delivery
- Re: Protected Mail System
- Re: Protected Mail Request
- Re: Secure SMTP Message
- Re: Extended Mail System
- Re: Error
- Re: Message Error
- Re: Administration
- Re: Test
- Re: Thank you for delivery
- Re: Failure
- Re: Bad Request
- Re: Delivery Server
- Re: Mail Server
- Re: SMTP Server
- Re: Notify
- Re: Status
- Re: Extended Mail
- Re: Encrypted Mail
- Please confirm my request.
- ESMTP [Secure Mail System #334]: Secure message is attached.
- Partial message is available.
- Waiting for a Response. Please read the attachment.
- First part of the secure mail is available.
- For more details see the attachment.
- For further details see the attachment.
- Your requested mail has been attached.
- Protected Mail System Test.
- Secure Mail System Beta Test.
- Forwarded message is available.
- Delivered message is attached.
- Encrypted message is available.
- Please read the attachment to get the message.
- Follow the instructions to read the message.
- Please authenticate the secure message.
- Protected message is attached.
- Waiting for authentification.
- Protected message is available.
- Bad Gateway: The message has been attached.
- SMTP: Please confirm the attached message.
- You got a new message.
- Now a new message is available.
- New message is available.
- You have received an extended message. Please read the instructions.
- message.
- msg.
- details.
- data.
- document.
- readme.
- here
- hi
- hello
- thanks!
- approved
- corrected
- patched
- improved
- important
- read it immediately
- Your details.
- Your document.
- I have received your document. The corrected document is attached.
- I have attached your document.
- Your document is attached to this mail.
- Authentication required.
- Requested file.
- See the file.
- Please read the important document.
- Please confirm the document.
- Your file is attached.
- Please read the document.
- Your document is attached.
- Please read the attached file!
- Please see the attached file for details.
- your
- my
- approved
- important
- document.
- file.
- details.
- information.
- letter.
- product.
- website.
- application.
- screensaver.
- bill.
- word document.
- excel document.
- data.
- message.
- text.
- document_all.
- [ext].txt
- [ext].doc
- [ext].pif
- [ext].exe
- [ext].scr
- +++ Attachment: No Virus found +++ MessageLabs AntiVirus - www.messagelabs.com
- +++ Attachment: No Virus found +++ Bitdefender AntiVirus - www.bitdefender.com
- +++ Attachment: No Virus found +++ MC-Afee AntiVirus - www.mcafee.com
- +++ Attachment: No Virus found +++ Kaspersky AntiVirus - www.kaspersky.com
- +++ Attachment: No Virus found +++ Panda AntiVirus - www.pandasoftware.com
- ++++ Attachment: No Virus found ++++ Norman AntiVirus - www.norman.com
- ++++ Attachment: No Virus found ++++ F-Secure AntiVirus - www.f-secure.com
- ++++ Attachment: No Virus found ++++ Norton AntiVirus - www.symantec.de
Propagation (LAN, P2P networks, FTP and HTTP folders)
- my shared folder
- download
- ftp
- htdocs
- http
- upload
- shar
- icq
- bear
- lime
- morpheus
- donkey
- mule
- kazaa
- shared files
- Kazaa Lite 4.0 new.exe
- Britney Spears Sexy archive.doc.exe
- Kazaa new.exe
- Britney Spears porn.jpg.exe
- Harry Potter all e.book.doc.exe
- Britney sex xxx.jpg.exe
- Harry Potter 1-6 book.txt.exe
- Britney Spears blowjob.jpg.exe
- Harry Potter e book.doc.exe
- Britney Spears cumshot.jpg.exe
- Harry Potter.doc.exe
- Britney Spears fuck.jpg.exe
- Harry Potter game.exe
- Britney Spears.jpg.exe
- Harry Potter 5.mpg.exe
- Britney Spears and Eminem porn.jpg.exe
- Matrix.mpg.exe
- Britney Spears Song text archive.doc.exe
- Britney Spears full album.mp3.exe
- Eminem.mp3.exe
- Britney Spears.mp3.exe
- Eminem Song text archive.doc.exe
- Eminem Sexy archive.doc.exe
- Eminem full album.mp3.exe
- Eminem Spears porn.jpg.exe
- Ringtones.mp3.exe
- Eminem sex xxx.jpg.exe
- Ringtones.doc.exe
- Eminem blowjob.jpg.exe
- Altkins Diet.doc.exe
- Eminem Poster.jpg.exe
- American Idol.doc.exe
- Cloning.doc.exe
- Saddam Hussein.jpg.exe
- Arnold Schwarzenegger.jpg.exe
- Windows 2003 crack.exe
- Windows XP crack.exe
- Adobe Photoshop 10 crack.exe
- Microsoft WinXP Crack full.exe
- Teen Porn 15.jpg.pif
- Adobe Premiere 10.exe
- Adobe Photoshop 10 full.exe
- Best Matrix Screensaver new.scr
- Porno Screensaver britney.scr
- Dark Angels new.pif
- XXX hardcore pics.jpg.exe
- Microsoft Office 2003 Crack best.exe
- Serials edition.txt.exe
- Screensaver2.scr
- Full album all.mp3.pif
- Ahead Nero 8.exe
- netsky source code.scr
- E-Book Archive2.rtf.exe
- Doom 3 release 2.exe
- How to hack new.doc.exe
- Learn Programming 2004.doc.exe
- WinXP eBook newest.doc.exe
- Win Longhorn re.exe
- Dictionary English 2004 - France.doc.exe
- RFC compilation.doc.exe
- 1001 Sex and more.rtf.exe
- 3D Studio Max 6 3dsmax.exe
- Keygen 4 all new.exe
- Windows 2000 Sourcecode.doc.exe
- Norton Antivirus 2005 beta.exe
- Gimp 1.8 Full with Key.exe
- Partitionsmagic 10 beta.exe
- Star Office 9.exe
- Magix Video Deluxe 5 beta.exe
- Clone DVD 6.exe
- MS Service Pack 6.exe
- ACDSee 10.exe
- Visual Studio Net Crack all.exe
- Cracks & Warez Archiv.exe
- WinAmp 13 full.exe
- DivX 8.0 final.exe
- Opera 11.exe
- Internet Explorer 9 setup.exe
- Smashing the stack full.rtf.exe
- Ulead Keygen 2004.exe
- Lightwave 9 Update.exe
- The Sims 4 beta.exe
Protect your devices from malware with F‑Secure Total
Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.
- Award‑winning antivirus and malware protection
- Online browsing, banking, and shopping protection
- 24/7 online identity and data breach monitoring
- Unlimited VPN service to safeguard your privacy
- Password manager with private data protection
Choose how many devices you want to protect to get started.
- Free customer support
- Cancel anytime
- The trial does not obligate you to buy the product
After 30 days your subscription will renew automatically for one year at €69.99.
More Support
Community
Ask questions in our Community.
User guides
Check the user guide for instructions.
Contact Support
Chat with with or call an agent.
Submit a Sample
Submit a file or URL for analysis.
)
)