ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Netsky.B outstrips MyDoom

James Pearce ZDNet Australia

Published: 24 Feb 2004 08:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

E-mail inboxes are being swamped as Netsky.B continues to increase its infection rate.

The worm first appeared on 17 February and appears to have originated in the Netherlands. MessageLabs, an e-mail management company, claims to have stopped more than 1.3 million email since the virus started spreading, and believes the infection rate is increasing rapidly. Symantec have rated the worm as severe. This means the worm is a dangerous threat and is difficult to contain.

The worm does require the user to open the attachment with the e-mail. "These days it's less to do with technology, with the code of the virus, and more to do with social engineering," David Banes of MessageLabs told ZDNet Australia.

Netsky.B scans the hard drives and shared drives of an infected computer for e-mail addresses and then uses its own SMTP engine to mail itself to those addresses. The worm also searches for folder names containing "share" or "sharing" and copies itself to those folders using a variety of file names.

The worm appears in the Inbox using a spoofed "from" address and a subject line chosen from one of the following: hi, hello, read it immediately, something for you, warning, information, stolen, fake, unknown. The body of the e-mail contains a variety of messages, and the attachment will normally have a double-file name or be a zip file. When the file is opened it displays a message "The file could not be opened!" before going to work.

In the last 24 hours, MessageLabs has stopped more than 10 times as many Netsky.B worms as MyDoom worms.

Symantec has a removal tool here.

For more coverage on ZDNet Australia, click here.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
68 out of 158 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Sentry Posts Blog

Toshiba developing quantum repeater

Toshiba is developing a device it hopes will allow for global quantum key distribution. The company is developing a quantum repeater, a device to regenerate a quantum key once quantum... More

Post a comment

Nasa hacker loses last-ditch appeal

Self-confessed Nasa hacker Gary McKinnon has lost his appeal to Home Secretary Jacqui Smith against extradition to the US. In an email sent to ZDNet.co.uk on Monday, McKinnon's... More

3 comments

Up to 1.7m MoD personal details missin...

The potential number of people affected by the the loss of a hard disk containing MoD details could be a high as 1.7 million, defence minister Bob Ainsworth told parliament on Monday. In... More

1 comment