Netsky-B Worm Spreading Widely
Posted on 18.02.2004
Bookmark and Share
(http://www.viruslist.com/eng/alert.html?id=930701" target="_blanK">Doomjuice.b. Sophos, a world leader in protecting businesses against spam and viruses, is warning of a new worm called Netsky-B (W32/Netsky-B). It has already received several reports of this worm spreading in the wild.

The worm spreads via email - forwarding itself to email addresses found on the hard drives of infected computers - and Windows network shares.

When forwarding itself, the worm spoofs the 'From:' field to trick unsuspecting computer users into running the malicious code. Infected emails arrive with a variety of different subject lines and message texts. An attached file has a double extension.

The worm chooses from a selection of filenames when copying itself to shared folders. These names vary from 'angels.pif', 'dictionary.doc.exe' and 'programming basics.doc.exe' to 'sex sex sex sex.doc.exe' and 'hardcore porn.jpg.exe'.

"Worms like this, which don't just rely on email to spread, underline the need for anti-virus protection on the desktop - computer users shouldn't just be relying on email scanning for protection," said Carole Theriault, security consultant, Sophos. "Netsky-B is tricky to identify because of the wide variety of subject lines and message texts, but blocking all files with double extensions is an easy way to avoid infection."





Spotlight

OpenBSD team forks OpenSSL to create safer SSL/TLS library

Posted on 22 April 2014.  |  Members of the OpenBSD project have begun working on a free version of the SSL/TLS protocol. They are not starting from scratch, but have forked OpenSSL to create a new, more secure option which they have dubbed LibreSSL.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Tue, Apr 22nd
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //