Advertisement
Promo

Security threats Toolkit

Netsky variant uses compression trick

Michael Kanellos CNET News

Published: 15 Oct 2004 11:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Virus hunters at McAfee have identified a new variant of the Netsky virus and rate it as a medium risk.

Like other Netsky viruses, the W32/Netskyag@MM offshoot uses an email to gain entry and install itself into several files via the Windows directory. Once installed, it harvests email addresses from the infected machine and sends out copies of itself in messages that look like they're from people on the email database in the infected computer.

The virus differs from earlier versions in that it uses different compression technologies when sending itself out, a representative for security software maker McAfee said on Thursday. This makes it more difficult to detect.

The subject line on the infected emails varies, with about 30 different ones identified so far. Most seem to be in Portuguese or a version of the language. Subject lines include "algo a mais" and "tudo sobre voce sabe". The message in the email and the attachment use the same dialect and also vary.

A number of infections are coming from Brazil, McAfee said.

The security company has released a workaround for the virus. More information can be found at McAfee's Web site.

The Netsky virus has been one of the most prolific security threats of 2004, infecting millions of computers and spawning more than 25 variants. The virus has also been used to seed computers to knock out Web sites with denial-of-service attacks. The suspected author of Netsky and the Sasser virus, 18-year-old Sven Jaschan, was arrested earlier this year and currently awaits trial.

The Portuguese Netsky variant was discovered on 13 October. McAfee's Avert lab, which studies incoming viruses, raised the risk profile to "medium" on Thursday.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
70 out of 130 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters