On The Insider: Shields Reveals MJ Relationship Secrets
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Feb 18, 2004 7:50:00 PM

The second version of a two-day-old virus, Netsky, has started spreading more successfully than its parent, antivirus researchers said on Wednesday.

The new variant, Netsky.B, uses e-mail to sends copies of itself to potential victims--people with computers running the Microsoft Windows operating system. It also stores copies of itself in shared directories, apparently to facilitate its propagation via file-sharing networks.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


"The author, it seems, has done something to improve the virus's spread," said Alfred Huger, the senior director of engineering for security firm Symantec.

Symantec rated the virus a three on its five-point scale, while rival Network Associates gave the program a "medium" threat rating. The worm appears only to want to spread itself and not to launch an attack.

E-mail messages carrying Netsky.B come with almost 50 different subject lines and body text, from "I have your password!" to the succinct "OK." It carries a file attachment with a double extension, which can arrive in a variety of formats, including a ZIP archive. The virus sends e-mail on its own and also copies itself to shared directories and so can spread through Kazaa, BearShare, LimeWire and other peer-to-peer networks.

"On the mailing side, this is one of the more successful viruses," said Craig Schmugar, a virus research manager with Network Associates' antivirus and vulnerability emergency response team.

Schmugar said its success is somewhat puzzling because the social engineering--the way the virus's author words the e-mail that carries the program--is so minimalist.

However, the virus may not be wordy, but its e-mail messages do have a significant number of variations, Chris Belthoff, a senior security analyst at Lynnfield, Mass.-based Sophos, noted in a statement.

"Netsky.B is tricky to identify because of the wide variety of subject lines and message texts, but blocking all files with double extensions is an easy way to avoid infection," he said. The use of double extensions--such as .jpeg.exe--is a common trick among virus writers because Microsoft Outlook will remove the final extension hiding the true file type.

Of the two viruses that started spreading this week--Netsky.B and Bagle.b--the latter is more serious, according to Symantec's Huger.

"The Bagle virus's spread was about the same but its payload is much more dangerous," he said.

More information on the virus can be found at CNET Reviews' Virus Center.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 64 Talkback(s)
my guess is
"These people have to know that taking down networks and systems for 'fun' is morally wrong, so why do they do it? "

because no one likes them, or is a government testing asults for the future, but I lean towards the script kiddie with no life... (Read the rest)
Posted by: V Sanders Posted on: 02/20/04 You are currently: a Guest | | Terms of Use
Do NOT open unknow attachements  DonB_z | 02/18/04
Better yet: do NOT install Windows! Needless problems precluded!  Bobby Sskcat | 02/18/04
you're not much better (nt)  ryusen | 02/18/04
he is much better  stephen732@... | 02/18/04
maybe we need to require a lecense  JWatson77 | 02/19/04
Let me guess: a Windows virus! Yaaaawwn...  Bobby Sskcat | 02/18/04
Not a WIndows virus, an Outlook virus.  Jomo_z | 02/18/04
Better Yet..  Bobby Sskcat | 02/18/04
Read, Comprehend and Then Post!  ShadeTree | 02/18/04
Ummm..YOU read, comprehend, yada yada!  Bobby Sskcat | 02/18/04
My point exactly  ShadeTree | 02/19/04
I use Mozilla and...  Heatlesssun | 02/18/04
not exactly  stephen732@... | 02/18/04
Coincedence?  Spoon Jabber | 02/18/04
When ordinary users get around to using Linux  jfrankcarr | 02/18/04
Blame  pschroeder@... | 02/18/04
well...  ryusen | 02/18/04
don't fear what you don't know  stephen732@... | 02/18/04
Well, for right now I'm 100% Microsoft.  jfrankcarr | 02/18/04
dont get locked in.  Suicida| | 02/19/04
Blame Bill?  dwest_z | 02/19/04
You're right, not legally, but  jfrankcarr | 02/19/04
Oh puhleeze!!!  Confused by religion | 02/18/04
Also Milly...  The Real Bitch | 02/18/04
So Sad....  middle of nowhere | 02/18/04
So do I, among other systems...  Confused by religion | 02/18/04
Silly "*****", tricks are for kids  Spoon Jabber | 02/18/04
Who writes these things??  FilledOut | 02/18/04
Brave men of noble causes  Bobby Sskcat | 02/18/04
you punk  cookingwithcat | 02/18/04
WTF?!??!?!?! (nt)  ryusen | 02/18/04
A lot of the newer ones are zombie creators  jfrankcarr | 02/18/04
re: Who writes these things??  cookingwithcat | 02/18/04
I'd write a Linux virus but...  Heatlesssun | 02/18/04
Social engineering  Mark Gist | 02/18/04
The problem is...  vferrara | 02/18/04
EX-actly (NT)  pschroeder@... | 02/18/04
Maybe  jfrankcarr | 02/18/04
why would users need this?  ryusen | 02/18/04
Here is a clever one...  The Real Bitch | 02/18/04
Harder to attack  jfrankcarr | 02/18/04
Linux  voska | 02/18/04
Macintosh Security  middle of nowhere | 02/18/04
wishful thinking  cookingwithcat | 02/18/04
What profit?  Spoon Jabber | 02/19/04
I'm no linux expert  skeptic tank | 02/18/04
Im sure it is possible  Suicida| | 02/19/04
Please Go Here...  The Real Bitch | 02/18/04
Funny  skeptic tank | 02/18/04
Sorry, but...  The Real Bitch | 02/18/04
I was talking about the virus happy  skeptic tank | 02/18/04
Evolution...  Confused by religion | 02/18/04
That may be true miss outlook mvp  skeptic tank | 02/18/04
Neither is Outlook...  Confused by religion | 02/19/04
Microsoft's Responsibility ...  cookingwithcat | 02/18/04
Home users are the real battleground  jfrankcarr | 02/18/04
re: Home users are the real battleground  cookingwithcat | 02/18/04
Wasted talent or no ethics?  itguyinde | 02/19/04
Removed double extensions?  Jim Mie | 02/19/04
Windows setting, not Outlook.  jfrankcarr | 02/19/04
ISPs need to stop this stuff  nroose | 02/19/04
RE: ISPs need to stop this stuff  TickedOffSysAdmin | 02/19/04
oh no  V Sanders | 02/20/04
my guess is  V Sanders | 02/20/04

What do you think?

SmartPlanet

advertisement
Click Here