Worm:W32/NetSky.J

Classification

Category :

Malware

Type :

Email-Worm

Aliases :

NetSky.J, W32/NetSky.J@mm, I-Worm.NetSky.j, W32.NetSky.J@mm

Summary

A new variant of Netsky worm - Netsky.J was found on March 8th, 2004.

Removal

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note: You need administrative rights to change the settings.

Technical Details

Descriptions of all previous NetSky worm variants can be found here:

The worm's file is a PE executable file 27648 bytes long.

NetSky.J worm has a few modifications comparing to previous variants:

  • The worm uses a different mutex: "SkYnEt_AVP"
  • The worm has message for Bagle And Mydoom worm authors in the same lines as previous ones.
  • The worm uses the following subject texts:
    • Your product
    • Your letter
    • Re: corrected homework
    • Re: I've found your document
    • Re: Your bill
    • Re: hello again
    • Re: hi again
    • Re: part 3
    • Re: important document part 2
    • Re: important
    • Re: Your data
    • Re: Your application
    • Re: your music
    • Re: excel document
    • Re: Re: Re: word document
    • Re: Your details
    • Re: My details
    • Re: Your requested file
    • Re: Read it immediately
    • Re: Approved
    • Re: Your software
    • Re: my memberlist
    • Re: Your document
    • Re: Your file
    • Re: Your important document
    • www.%s.tripod.com
    • Hi Mr. %s
    • Moi %s
    • He %s
    • Yours faithfully, %s
    • Message to %s
    • Hi Mrs. %s
    • Is %s.doc yours?
    • Is %s.xls yours?
    • Whats up %s
    • www.paypal.com/%s
    • Na %s
    • Best %s
    • Love %s
    • Good morning %s
    • Have a good day %s
    • Dear %s
    • To %s , it's me
    • Welcome %s
    • Moin %s
    • Hello %s
    • Your account %s is expired!
    • Hey %s
    • Hi %s
    • www.%s.freepage.com, your website
    • Hi %s, your product
    • Hello %s, your letter
    • Re: Hi %s, your archive
    • Re: %s, your text
    • Re: Hello %s, your bill
    • Re: Hi %s, your details
    • Re: Hello %s, my details
    • Re: Hi %s, your word file
    • Re: Hello %s, your excel file
    • Re: Hi %s, details
    • Re: Hello %s, Approved
    • Re: Hello %s, your software
    • Re: Hi %s, your music
    • Re: Dear %s, Here
    • Re: Re: Re: Hello %s, your document
    • Re: Hi %s
    • Re: Dear %s, Hi
    • Re: Re: Hi %s, your message
    • Re: Here %s, your picture
    • Re: Hi %s, here is the document
    • Re: Hello %s, your document
    • Re: %s, thanks!
    • Re: Re: %s, thanks!
    • Re: Re: Hi %s, document
    • Re: Hello %s, document
    Where %s will be substituted by some text.
  • The worm uses the following message body texts:
    • My details are in the attached file.
    • I have corrected your document.
    • Please do not forget to read the important document.
    • I have an interesting document about you.
    • The sample is attached.
    • Your personal document is attached.
    • Your file is attached to this mail.
    • Note that I have attached your file.
    • The important document is attached.
    • Please read the document. It's important.
    • Your document is attached to this mail.
    • See the attachment for further details.
    • Your file is attached. Use this password for the file: %i.
    • Please read the attached file. Password for the file is %i.
    • Please have a look at the attached file. Password for decrypting is %i.
    • See the attached file for details. Password is %i.
    • Here is the file. My password is %i.
    • Your document is attached. Your password is %i.
  • The worm installs itself to system as avpguard.exe file.