acerca de
contacto
términos y condiciones
glosario
  > buscador
 
  > búsqueda avanzada
Herramientas contra:
 

(c) Paolo Monti
  Enciclopedia Virus
es una página de
 >  VIRUS: WIN32/NETSKY.C
  descripción
  nombre: Win32/Netsky.C
  aliases: Netsky.C, Moodown.C, I-Worm.Moodown.c, W32/Netsky.C, W32/Netsky.c@MM, W32/Netsky.C.worm, W32/Netsky-C
  tipo: Gusano de Internet
  fecha: 25/02/2004
  gravedad general:
Alta
  distribución:
Alta
  daño:
Alto
  destructivo: Si
  origen: Desconocido
  nombre asignado por: ESET

 >  INFORMACION
Gusano basado en el Netsky.A, reportado el 25 de febrero de 2004. El gusano libera copias de si mismo, con una o dos extensiones, copiándose también en carpetas compartidas. Intenta borrar algunos productos antivirus y a los gusanos Mydoom A y B. También se propaga por redes P2P. Se han recibido reportes que indicarían un alto nivel de propagación.

 >  CARACTERISTICAS

Análisis:

El gusano es un archivo de 25,352 bytes (Petite), 24,064 (UPX) o 28,160 bytes (Aspack), según la utilidad utilizada para comprimirlo. En ocasiones puede medir más, ya que agrega bytes sin sentido para no medir siempre lo mismo.

Puede llegar en un mensaje como el siguiente:

De: [una dirección falsa]

Asunto: [uno de los siguientes]

  [vacío]
  believe me
  dear
  Delivery Failed
  denied!
  error
  exception
  excuse me
  fake?
  good morning
  hello
  Here is it
  hey
  hi
  illegal...
  I"m back!
  important
  info
  its me
  last chance!
  lol
  moin
  notice!
  notification
  oh
  private?
  question
  Question
  re:
  Re: <5664ddff?$??2>
  Re: does it?
  Re: does it?
  Re: excuse me
  Re: hello
  Re: hey
  Re: hi
  Re: important
  Re: information
  Re: Re: Re: Re:
  Re: unknown
  read it immediatelly
  report
  something for you
  Status
  stolen
  take it
  trust me
  warning
  what"s up?
  Yep
  you?

Texto del mensaje: [uno de los siguientes]

  [vacío]
  *lol*
  ;-)
  [...]
  [?}
  [[[Failure]]]
  [09580985869gj]
  [Antispam complete]
  [Attached Msg]
  [Attachment from Poland]
  [Attachment Signature 34933920]
  [Automailer]
  [bad gateway]
  [Click the attachment to decrypt]
  [Deliver Error]
  [Failed message available]
  [Mail failed]
  [Message Error]
  [null]
  [scanned by norton antivirus]
  [Server Error]
  [Transfer complete]
  [Warning from the Government]
  a crazy doc about you
  abuse?
  account?
  already?
  another pic, have fun! ... :-]
  Antispam is turned off. See file!
  are you a photographer?
  are you a teacherin the picture?
  are you cranky?
  are you the naked one?
  are you the naked person!
  are you the one?
  attachi#
  Authentification required. Read the att...
  be mad?
  best?
  bob the builder
  child or adult?
  child porn?
  classroom test of you?
  copyright?
  correct it!
  did you ask me for that?
  did you know from this document?
  did you know that?
  did you see her already?
  did you sent it to me?
  do not give up!
  do not open the attachment!
  do not show this anyone!
  do not use my document!
  do not use this creditcard!
  do not visit the pages on the list I se...
  do you have an orgasm in the picture?
  do you have sex in the picture?
  do you have the bug also?
  do you have?
  do you know the thief?
  do you know this????
  do you think so?
  doc about me?
  doc?
  docs?
  does it belong to you?
  does it belong to you?
  does it match?
  does it matter?
  drugs? ...
  excellent!
  explain!
  fast food...
  feel free to use it.
  File is bad.
  File is damaged.
  File is self-decryting.
  forgotten?
  from the chatter (my photo!)
  from your lover ;-)
  gonna?
  good work!
  great job!
  great xxx!
  great!
  greetings
  help attached
  her.
  here is it.
  here is my advice.
  here is my photo!
  here is the $%%454$
  here is the [censored]
  here is the document.
  here is the next one!
  here is yours!
  here, the cheats
  here, the introduction
  here, the serials
  how?
  i am desperate
  i am speachless about your document!
  I don"t know your document!
  i don"t think so.
  i don"t want your xxx pics!
  i found that about you!
  i found this document about you.
  i have received this.
  I have your password!
  i hope thats not true!
  i know your document!
  i like your doc!
  i lost that
  i need you!
  i saw you last week!
  I "ve found your bill!
  I wait for an answer!
  i wait for your comment about it.
  i want more...
  illegal st. of you?
  important?
  in your mind?
  incest?
  information about you?
  Instant patches.
  instruct me about this!
  is that criminal?
  is that possible?
  is that the reality?
  is that true?
  is that your account?
  is that your account?
  is that your attachment?
  is that your beast?
  is that your car?
  is that your car?
  is that your cd?
  is that your creditcard?
  is that your domain?
  is that your family?
  is that your finger?
  is that your message?
  is that your name?
  is that your photo?
  is that your porn pic?
  is that your privacy?
  is that your slip?
  is that your TAN?
  is that your website?
  is that your wife?
  is that your work?
  is that yours?
  is the pic a fake?
  is this information about you?
  it"s a secret!
  its private from me
  it"s so similar as yours!
  i"ve found it about you
  kill him on the picture!
  kill the writer of this document!
  let it!
  lets talk about it!
  Login required! Read the attachment!
  love letter?
  man or women?
  meaning of that?
  message?
  Microsoft
  misc. and so on. see you!
  modifications?
  money?
  msg
  my advice....
  never!
  new patch is available!
  ok...
  old photos about you?
  only encrypted!
  pages?
  personal message!
  picture?
  poor quality!
  possible?
  pretty pic about you?
  pwd?
  read it immediately!
  read the details.
  really?
  reply
  schoolfriend?
  see this!
  see your name!
  solve the problem!
  something about you!
  something is going ...
  something is going wrong!
  something is not ok
  stuff about you?
  such as yours?
  take it easy!
  tell me more about your document!
  test it
  that is interesting...
  that"s a funny text.
  that"s not the truth?
  thats wrong!
  the information is wrong!
  the truth?
  this file is bad!
  this is an attachment message!
  this is nothing for kids!
  time to fear?
  Transaction failed. Show the doc!
  trial?
  try this patch!
  what do you think about it?
  what means that?
  what still?
  what?
  who?
  why should I?
  why?
  wrong calculation! (see the attachment!...
  xxx ?
  xxx about you?
  xxx service
  yes.
  you are a bad writer
  you are bad
  You are infected. Read the details!
  you are naked in this document!
  you are sexy in this doc!
  you cannot hide yourself! (see photo)
  you earn money, see the attachment!
  you feel the same.
  you have a sexy body in the pic!
  you have done a mistake in the document...
  you have tried to steal!
  you look like an ape!
  you look like an rat?
  you won the rk!
  your account is expired!
  your are naked?
  your attachment? verify it.
  Your bill.
  your body?
  your design is not good!
  your document is not good
  your document is silly!
  your eyes?
  your face?
  your hero in the picture?
  your icq number?
  your job? (I found that!)
  your lie is going around the world!
  your name is wrong!
  your personal record?
  your photo is poor
  Your provider will be disabled!
  your TAN number?
  yours?

Datos adjuntos: [uno de los siguientes nombres]

  454543403
  aboutyou
  associal
  attach2
  attachment
  auction
  bill
  birth
  card
  class_photos
  concert
  creditcard
  death
  description
  details
  dinner
  disco
  doc
  doc_ang
  document
  final
  found
  freaky
  friend
  id
  image
  important
  incest
  information
  injection
  intimate stuff
  jokes
  letter
  location
  mail2
  mails
  masturbation
  material
  me
  message
  misc
  moonlight
  more
  msg
  msg2
  music
  myaunt
  mydate
  naked1
  naked2
  news
  nomoney
  note
  nothing
  number_phone
  object
  old_photos
  part2
  party
  paypal
  pic
  portmoney
  poster
  posting
  privacy
  product
  ps
  ranking
  regards
  regid
  release
  response
  schock
  secrets
  sexual
  sexy
  shower
  story
  stuff
  swimmingpool
  talk
  tear
  textfile
  topseller
  transfer
  trash
  undefinied
  unfolds
  update
  violence
  visa
  warez
  webcam
  website
  wife
  word_doc
  worker
  your_stuff
  yours

El adjunto podrá tener alguna de estas extensiones:

  .com
  .doc
  .doc.com
  .doc.exe
  .doc.pif
  .doc.scr
  .exe
  .htm
  .htm.com
  .htm.exe
  .htm.pif
  .htm.scr
  .pif
  .rtf
  .rtf.com
  .rtf.exe
  .rtf.pif
  .rtf.scr
  .scr
  .txt
  .txt.com
  .txt.exe
  .txt.pif
  .txt.scr
  .zip

Cuando se ejecuta, crea los siguientes archivos en el sistema infectado:

  c:\windows\winlogon.exe

De acuerdo a la versión de sistema operativo, las carpetas "c:\windows" y "c:\windows\system32" pueden variar ("c:\winnt", "c:\winnt\system32", "c:\windows\system").

Crea la siguiente entrada en el registro:

  HKLM\SOFTWARE\Microsoft\Windows
  \CurrentVersion\Run
  ICQNet = c:\windows\winlogon.exe -stealth

Acciones:

El gusano busca en las unidades de disco de la C a la Y (que no sean CD-ROMS), carpetas cuyo nombre contenga la cadena "SHAR" (esto incluye aplicaciones P2P como Kazaa, Kazaa Lite, BearShare, eDonkey2000, ICQ, Kmd, Limewire y Shareaza), y se copia a si mismo a dichas carpetas con los siguientes nombres:

  1000 Sex and more.rtf.exe
  3D Studio Max 3dsmax.exe
  ACDSee 9.exe
  Adobe Photoshop 9 full.exe
  Adobe Premiere 9.exe
  Ahead Nero 7.exe
  Best Matrix Screensaver.scr
  Clone DVD 5.exe
  Cracks & Warez Archive.exe
  Dark Angels.pif
  Dictionary English - France.doc.exe
  DivX 7.0 final.exe
  Doom 3 Beta.exe
  E-Book Archive.rtf.exe
  Full album.mp3.pif
  Gimp 1.5 Full with Key.exe
  How to hack.doc.exe
  IE58.1 full setup.exe
  Keygen 4 all appz.exe
  Learn Programming.doc.exe
  Lightwave SE Update.exe
  Magix Video Deluxe 4.exe
  Microsoft Office 2003 Crack.exe
  Microsoft WinXP Crack.exe
  MS Service Pack 5.exe
  Norton Antivirus 2004.exe
  Opera.exe
  Partitionsmagic 9.0.exe
  Porno Screensaver.scr
  RFC Basics Full Edition.doc.exe
  Screensaver.scr
  Serials.txt.exe
  Smashing the stack.rtf.exe
  Star Office 8.exe
  Teen Porn 16.jpg.pif
  The Sims 3 crack.exe
  Ulead Keygen.exe
  Virii Sourcecode.scr
  Visual Studio Net Crack.exe
  Win Longhorn Beta.exe
  WinAmp 12 full.exe
  Windows Sourcecode.doc.exe
  WinXP eBook.doc.exe
  XXX hardcore pic.jpg.exe

También intenta borrar las siguientes entradas, correspondientes a otros gusanos (Mydoom A y B), y software antivirus:

  HKCU\SOFTWARE\Microsoft
  \Windows\CurrentVersion\Run
  au.exe
  d3dupdate.exe
  Explorer
  KasperskyAv
  OLE
  Taskmon
  Windows Services Host

  HKLM\SOFTWARE\Microsoft
  \Windows\CurrentVersion\Run
  DELETE ME
  Explorer
  KasperskyAv
  msgsvr32
  Sentry
  service
  system.
  Taskmon
  Windows Services Host

  HKCR\CLSID
  \{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
  \InProcServer32

  HKCU\Software\Microsoft\Windows
  \CurrentVersion\Explorer\PINF

  HKLM\System\CurrentControlSet
  \Services\WksPatch

El gusano busca direcciones de correo en todas las unidades de disco de la C a la Z (excepto unidades de CD), dentro de archivos con las siguientes extensiones:

  .adb
  .asp
  .dbx
  .doc
  .eml
  .htm
  .html
  .msg
  .oft
  .php
  .pl
  .rtf
  .sht
  .tbb
  .txt
  .uin
  .vbs
  .wab

Cuando detecta una conexión a Internet establecida, el gusano comienza a propagarse a si mismo, evitando enviar mensajes a direcciones que contengan cualquiera de las siguientes cadenas:

  abuse
  antivi
  aspersky
  avp
  cafee
  fbi
  f-pro
  f-secur
  icrosoft
  itdefender
  orman
  orton
  spam
  ymantec

El día 26 de Febrero entre las 06:00 y las 08:59 de la mañana emite un sonido por el altavoz interno del ordenador.


 >  INSTRUCCIONES PARA ELIMINARLO

Eliminación Automática:

Future Time S.r.l., distribuidor italiano de NOD32 ha publicado una herramienta gratuita para desinfectar ordenadores afectados por este gusano sin necesidad de realizar pasos manuales y que puede ser descargada desde la siguiente dirección:

http://www.nod32.it/cgi-bin/mapdl.pl?tool=NetskyC

Eliminación Manual:

1. Desde Inicio, Ejecutar, escriba REGEDIT y pulse Enter para acceder al Registro del sistema.

2. Elimine bajo la columna "Nombre", la entrada "ICQNet" en la siguiente clave del registro:

  HKLM\SOFTWARE\Microsoft
  \Windows\CurrentVersion\Run

3. Cierre el editor del registro.

4. Reinicie el equipo y ejecute un antivirus actualizado para eliminar toda presencia del gusano.



  > lista de correo...  
 

Introduzca su email y reciba las últimas noticias sobre virus.

 
   

  > alertas  
  Los más vistos:  
 
   Win32/Etap.E
 
 
   Win32/Mytob.PI
 
 
   Win32/Sober.Y
 
 
   Win32/Bagle.BI
 
 
   Win32/Sober.R
 

  > últimos virus  
  Últimos 5 virus, con sus descripciones:  
 
   09-12 | Win32/Etap.E
 
 
   09-12 | LockScreen.HW
 
 
   09-12 | LockScreen.JN
 
 
   14-05 | Spy.Swisyn.AC
 
 
   14-05 | Win32/Witkinat.B
 

  > ránking  
  5 virus más detectados por INTECO-CERT para PYMES y Ciudadanos:  
 
   Win32/Netsky.P  |  36.20 %
 
 
   Win32/Netsky.B  |  29.80 %
 
 
   Win32/Netsky.Q  |  6.60 %
 
 
   Bagle.FU  |  3.50 %
 
 
   Zafi.Gen  |  2.50 %
 
 
facilitado por     
 

  > sabías que...  
 

... malware constituye cualquier software escrito con intenciones maliciosas que se infiltre en un ordenador sin autorización.

 

ENCICLOPEDIA VIRUS 2002 - Todos los derechos reservados powered by