Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Netsky AG - New variant in-the-wild

  Even though the author has been arrested, cloning of the virus continues on one of the worst email viruses since Klez.H   

As noted, Secunia provides a good summary of all AV vendors (as many have differing suffixes).  Thankfully, this new variant remains low-risk by most AV vendors currently. 

Secunia Information
http://secunia.com/virus_information/12662/

McAfee - W32/Netsky.ag@MM
http://vil.nai.com/vil/content/v_128905.htm

Symantec - W32.Netsky.AD@mm (currently rated Level 2)
http://www.sarc.com/avcenter/venc/data/w32.netsky.ad@mm.html
This variant of W32/Netsky is similar to previous variants. It bears the following characteristics:

* constructs messages using its own SMTP engine
* harvests email addresses from the victim machine
* spoofs the From: address of messages

Avoid all EMAIL attachments that end as follows:

  • .pif
  • .com
  • .scr
  • .bat
  • .zip