New Worm Alias- W32.Netsky.C@mm & W32.Netsky.D@mm (English Version Only)

Mar 02, 2004

Communilink has received many reports of these worms from the wild: W32.Netsky.C@mm & W32.Netsky.D@mm


"It is a mass-mailing worm that uses its own SMTP engine to send itself to email addresses it finds when scanning the hard drives and mapped drives. It use spoofed sender email address send itself out and the subject, body, and email attachment vary." --- HKCER

When the virus runs, it create mutex called "[]SystemsMutex". Then it copies itself to "%Windows%\WINLOGON.EXE " and adds a value to the registry to ensure this copy is run each time when Windows starts:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ICQ Net = "%Windows%\winlogon.exe -stealth"

  W32.Netsky.C@mm W32.Netsky.D@mm
Alias Netsky.C, I-Worm.Moodown.C, W32/Netsky.C@mm, Moodown.C, Worm.Somefool Netsky.D, I-Worm.Moodown.D, W32/Netsky.D@mm, Moodown.D, Worm.Somefool, W32/Netsky.D.worm, Win32.Netsky.D, I-Worm.Netsky.d, W32.Netsky.gen@mm
Subject Delivery Failed, Status, report, question, trust me, hey, Re: excuse me, read it immediately, hi, Re: does it?, Yep, important, hello, dear, Re: unknown, fake?, warning, moin, what's up?, info, Re: information, Here is it stolen, private?, good morning, illegal..., error, take it, re:, Re: Re: Re: Re:, you?, something for you, exception, Re: hey, excuse me, Re: hi, Re: does it?, Re: important, Re: hello, believe me, Question, denied!, notification, Re: <5664ddff?$??o2>, lol, last chance!, I'm back!, its me, notice! Re: Your website, Re: Your product, Re: Your letter, Re: Your archive, Re: Your text, Re: Your bill, Re: Your details, Re: My details, Re: Word file Re: Excel file, Re: Details, Re: Approved, Re: Your software, Re: Your music, Re: Here, Re: Re: Re: Your document, Re: Hello, Re: Hi, Re: Re: Message, Re: Your picture, Re: Here is the document, Re: Your document, Re: Thanks!, Re: Re: Thanks!, Re: Re: Document, Re: Document
Body Randomly chosen from:
<Deliver Error>, <Message Error>, <Server Error>, what means that?, help attached, <...>, ok..., <Attachment from Poland>, that is interesting..., i wait for your comment about it., such as yours?, read the details., gonna?, here is the document., *lol*, read it immediately!, i found that about you!, your hero in the picture?, yours?, here is it., illegal st. of you?, is that true?, account?, is that your name?, picture?, message?, is that your account?, pwd?, I wait for an answer!, abuse?, is that yours?, you are a bad writer ,I don't know your document!, <Mail failed>, I have your password!, you won the rk!, something about you!, classroom test of you?, kill the writer of this document!, old photos about you?, i hope thats not true!, your name is wrong!, does it match?, i found this document about you., time to fear?, really?, do you know this????, i know your document!, did you sent it to me?, this file is bad!, why should I?, pages?, her., another pic, have, un! ... :->, test it, child porn?, greetings, xxx ?, stuff about you?, your document is not good, something is going wrong!, your photo is poor, information about you?, the information is wrong!, doc about me?, kill him on the picture!, from the chatter (my photo!), from your lover ;-), love letter? here, the serials, are you a teacherin the picture?, here, the introduction, is that criminal?, here, the cheats, i like your doc!, what do you think about it?, that's a funny text., that's not the truth?, do you have?, instruct me about this!, i lost that, i am speachless about your document!, is that the reality?, reply, msg, your design is not good!, important?, your TAN number?, take it easy!, why? you are naked in this document!, thats wrong!, your icq number?, i am desperate, modifications?, your personal record?, yes. misc. and so on. see you!, your attachment? verify it., you earn money, see the attachment!, is that your attachment?, is that your website?, you feel the same., meaning of that?, possible?, you have tried to steal!, did you ask me for that?, you are bad, your job? (I found that!), is that possible?, something is going ..., something is not ok, did you know from this, document?, wrong calculation! (see the attachment!..., never!, poor quality! good work!, excellent!, great!, i don't think so., pretty pic about you?, docs?, schoolfriend?, <Warning from the Government>, <09580985869gj>, <?} i want more..., here is the next one!, attachi#, did you see her already?, is that your wife?, is that your creditcard?, is that your photo?, do you think, so?, do you have the bug also?, already?, forgotten?, drugs? ..., does it matter?, i have received this., best?, the truth?, your body?, your eyes?, your face?, File is self-decryting., File is damaged., File is bad., i saw you, last week!, xxx service, your account is expired!, you cannot hide yourself!, (see photo), copyright?, what still?, who?, how?, <bad gateway>, only, encrypted!, personal message!, my advice...., i've found it about you, <<<Failure>>>, <Attached Msg>, <scanned by norton antivirus>, great xxx!, man or women?, child or adult?, here is yours!, a crazy doc about you, xxx about you?, i don't want your xxx pics!, <Failed message available>, <Automailer>, doc?, trial?, what?, ;-), i need you!, correct it!, see this!, it's a secret!, this is nothing for kids!, it's so similar as yours!, is that your car?, do not give up!, great job!, here is the $%%454$, you are sexy in this doc!, incest?, let it!, you look like an ape!, you look like an rat?, be mad?, are you cranky?, bob the builder, did you know that?, money?, is that your car?, is this information about you?, is that your privacy?, is that your TAN?, is that your message?, is that your cd?, is that your finger?, your are naked?, is that your porn pic?, is that your work?, is that your family?, is that your beast?, is that your account?, is that your slip?, is that your domain?, are you the naked one?, are you the naked person!, are you the one?, does it belong to you?, do you have sex in the picture?, you have a sexy body in the pic!, your lie is going around the world!, <Transfer complete>, <Antispam complete>, lets talk about it!, do you know the thief?, are you a photographer?, you have done a mistake in the, document..., its private from me, do not show this anyone!, new patch is available!, this is an attachment message!, in your mind?, Microsoft fast food... , Your bill, try this patch!, do you have an orgasm in the picture?, <Click the attachment to decrypt>, <Attachment Signature 34933920>, Transaction failed. Show the doc!, I 've found your bill!, see your name!, You are infected. Read the details!, here is my advice., here is my photo!, here is the <censored>, feel free to use it., does it belong to you?, Login required! Read the attachment!, your document is silly!, is the pic a fake?, Antispam is turned off. See file!, Authentification required., Read the att..., solve the problem!, <null>, do not use my document!, do not open the attachment!, do not visit the pages on the list I se..., explain! tell me more about your document!, Your provider will be disabled!, Instant patches.
Randomly chosen from:
Your file is attached., Please read the attached file., Please have a look at the attached file., See the attached file for details., Here is the file., Your document is attached.

The attachment name is composed in several parts.

First part: document, asocial, msg, yours, doc, wife, talk, message, response, creditcard, description, details, attachment, pic, me, trash, card stuff, poster, posting, portmoney, textfile, moonlight, concert, sexy, information, news, note, number_phone, bill, mydate, swimmingpool, class_photos, product, old_photos, topseller, ps, important, shower, myaunt, aboutyou, yours, nomoney, birth, found, death, story, worker, mails, letter, more, website, regards, regid, friend, unfolds, jokes, doc_ang, your_stuff, location, 454543403, final, schock, release, webcam, dinner, intimate stuff, sexual, ranking, object, secrets, mail2, attach2, part2, msg2, disco, freaky, visa, party, material, misc, nothing, transfer, auction, warez, undefinied, violence, update, masturbation, injection, naked1, naked2, tear, music, paypal, id, privacy, word_doc, image, incest

Second part (or may be omitted): .txt, .rtf, .doc, .htm,

Third part: .exe, .scr, .com, .pif

Example: document.txt.exe, associal.rtf.scr

The attachment may also be sent inside a ZIP archive, for example,,

all_document.pif, application.pif, document.pif, document_4351.pif, document_excel.pif, document_full.pif, document_word.pif, message_details.pif, message_part2.pif, mp3music.pif, my_details.pif, your_archive.pif, your_bill.pif, your_details.pif, your_document.pif, your_file.pif, your_letter.pif, your_picture.pif, your_product.pif, your_text.pif, your_website.pif, yours.pif
New virus definition is available from anti-virus vendors to detect and remove this virus.

If you do not install any anti-virus program, you can download the following removal tools to clean it.



