Proland Software  Buy Antivirus software now!

Home
Antivirus products
Download Antivirus Software
Order On-line
Support
Email
Protector Plus Antivirus Software for
Antivirus Software for Windows XP and 2000
Antivirus Software for Windows Vista
Antivirus Software for Windows Me and 98
Antivirus Software for Exchange
Antivirus Software for NetWare
Protector Plus Console
Buy Antivirus software now!


SpamChoke Antispam
Software

Subscribe to Virus Alert
Mailing List

Enter your Email
(Ex : john@company.com)






Download Anti virus software

W32/Netsky.E Worm

Blueball Information about the W32/Netsky.E worm:

W32/Netsky.E is a mass mailing worm. This worm is a variant of W32/Netsky.C. The worm infects Windows systems. This worm spread through email and shared drives on network.

The infected email carries a fake 'From' address, picked up from the infected system.

The subject of the infected email will be any one of the following;

Announcement
Approved
Attention
Confirmation
Confirmation Required
Delivery Failed
Details
Expired account
Here is it
I'm back!
Love is
Question
Re: <5664ddff?$??º2>
Re: <censored>
Re: Approved
Re: Details
Re: Re: Re: Re: Re:
Thank you
Re: does it?
Re: excuse me
Re: hello
Re: hey
Re: hi
Re: important
Re: information
Re: unknown
Read this message
Registration confirm
Returned Mail
Schedule
Status
Thank You very very much
Thank you
Yep
You have 1 day left
You use illegal...
Your IP was logged
Your request was registered
automatic notification
automatic responder
believe me
dear
denied!
error
exception
excuse me
fake?
good morning
hello
hey
hi
hi, it's me
illegal...
important
info
its me
last chance!
lol
moin
notice!
notification
oh
please read
please reply
private?
question
re: read it immediatelly
read now!
registered?
report
something for you
stolen
take it
trust me
warning
what's up?
you?

The body of the email will be any one of the following;

Deliver Error>
*lol*
are you the naked person!
are you the one?
attachi#
be mad?
best?
bob the builder
child or adult?
child porn?
classroom test of you?
copyright?
correct it!
did you ask me for that?
did you know from this document?
did you know that?
did you see her already?
did you sent it to me?
do not give up!
do not open the attachment!
do not show this anyone!
do not use my document!
do not visit the pages on the list
I se... do you have an orgasm in the picture?
do you have sex in the picture?
do you have the bug also?
do you have?
do you know the thief?
do you know this????
do you think so?
;-)
<...>
<09580985869gj>
<<<Failure>>>
<?}
<Antispam complete>
<Attached Msg>
<Attachment Signature 34933920>
<Attachment from Poland>
<Automailer>
<Click the attachment to decrypt>
<Failed message available>
<Mail failed>
<Message Error>
<Server Error>
<Transfer complete>
<Warning from the Government>
<bad gateway>
<null>
<scanned by norton antivirus>
Antispam is turned off.
See file!
Authentification required.
Read the att..
.
The infected email has an attachment with any one of the following names;

454543403
aboutyou
associal
attach2
attachment
auction
bill
birth
card
class_photos
concert
creditcard
death
description
details
dinner
disco
doc
doc_ang
document
final
found
freaky
friend
id
image
important
incest
information
injection
intimate
stuff
jokes
letter
location
mail2
mails
masturbation
material
me
message
misc
moonlight
more
msg
msg2
music
myaunt
mydate
naked1
naked2
news
story
stuff
swimmingpool
talk
tear
textfile
topseller
transfer
trash
undefinied
unfolds
update
violence
visa
warez
webcam
website
wife
word_doc
worker
your_stuff
yours

The file extension of the infected attachment will be single or double extension with a combination of the following extensions;

.rtf, .txt, .doc, .htm, .exe, .scr, .com, .pif, .zip

Upon execution of the infected attachment, the worm copies itself as WINLOGON.EXE in the Windows folder. It creates a mutex SkyNet.cz to check the presence of the worm in system memory.

The worm modifies registry at the following location to run itself at the startup;

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

To propagate itself, the worm scans the files having the following extensions and collects all the available email addresses from the infected system and shared folders;

.php, .pl, .rtf, .sht, .tbb, .txt, .uin, .vbs, .wab, .adb, .asp, .dbx, .doc, .eml, .htm, .html, .msg, .oft

After this, the worm mails itself to these addresses using its own SMTP engine.

The worm may de-activate some variants of W32/Mydoom in the infected system.

This worm first appeared on March 1, 2004.

Blueball Other names of W32/Netsky.E worm:

This worm is also known as W32/Netsky.e@MM, WORM_NETSKY.E, Moodown.E.


Click here to download a 30 day Evaluation Copy of
Protector Plus anti virus software for your operating system

Blueball About Protector Plus Antivirus Software Packages:

Proland Software is the developer of Protector Plus range of antivirus software packages. Protector Plus 2007 is available for Windows Vista, Windows 95/98/Me, Windows XP, Windows NT/2000/2003 servers and workstations, MS-Exchange 2000/2003, MS-DOS and NetWare servers.

SpamChoke Antispam Software

New:
SpamChoke Antispam Software
Download Now!

Protector Plus range of antivirus products offer on-line virus detection and removal. All the packages have the ability to detect and isolate all types of viruses, trojans, worms and other types of malware.

These products are updated on a continuous basis and the latest upgrades for all the platforms are made available for downloading from this site.

Click here to order
Protector Plus Antivirus software
 

Buy Antivirus software now!


You can download the 30 day evaluation copy of the
antivirus software free of cost for these platforms:
Antivirus Software for Windows XP and 2000 Antivirus Software for Windows Me and 98 Antivirus Software for Exchange Antivirus Software for NetWare


HomeAntivirus productsDownload Antivirus SoftwareOrder On-lineEmail

Copyright © 2007 Proland Sofrware. All rights reserved.


Download Anti virus software