Skip to main content

Nightflyght

Classification

Category:

Malware

Type:

Worm

Aliases:

  • Nightflyght
  • Nightflyght

Summary

Nightflyght is a polymorphic Visual Basic Script worm.

Removal

Technical Details

Nightflyght.A worm spreads using Outlook and mIRC. The infected Outlook messages looks as follows:

Subject: Hi :-) Body:{script code}

The worm send itself as an embedded HTML, not as a separate attachment.

Nightflyght lowers Internet Explorer security zones and Windows Script Host (WSH) security settings:

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ HKCU\Software\Microsoft\Windows Script Host\Settings\TrustPolicyThe worm contains several payloads. If the day is 5th and in any month, it removes the desktop:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop

and changes the registered owner to 'NightFlight': HKLM\Software\Microsoft\Windows\CurrentVersion\RegisteredOwner

and the registered organization to 'Carpe Noctem': HKLM\Software\Microsoft\Windows\CurrentVersion\RegisteredOrganization

The worm also changes the wallpaper to a random bit map file found on the infected system:

HKCU\Control Panel\desktop\Wallpaper

Nightflight.A spreads via mIRC by modifying the Script.ini file. To do this, it uses file warning.htm that it drops in the Windows folder.

The worm affects Windows SE by executing Microsoft Agent and showing the following message:

Variant:Nightflyght.A

Nightflyght.A worm spreads using Outlook and mIRC. The infected Outlook messages looks as follows:

Subject: Hi :-) Body:{script code}

The worm send itself as an embedded HTML, not as a separate attachment. Nightflyght lower Internet Explorer security zones and WSH security settings:

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ HKCU\Software\Microsoft\Windows Script Host\Settings\TrustPolicy The worm contains several payloads. If the day is 5th and any month, it removes the desktop:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop changes the registered owner to 'NightFlight':

HKLM\Software\Microsoft\Windows\CurrentVersion\RegisteredOwner and the registered organization to 'Carpe Noctem':

HKLM\Software\Microsoft\Windows\CurrentVersion\RegisteredOrganization

The worm also changes the wallpaper to a random bit map file found on the infected system: HKCU\Control Panel\desktop\Wallpaper Nightflight.A spreads via mIRC by modifying the Script.ini file. To do this it uses file warning.htm that it drops in Windows folder. The worm affects Windows SE by executing Microsoft Agent and showing the following message: "The Nightflight is still out there!"

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.