>>新着対応済みウイルス
>>ウイルス危険度ランキング

>>最新ウイルスニュース

>>ウイルスINDEX/名称検索

ウイルス名
Win32.HLLM.Netsky.based(別名:NetSky.C)
発見日
2004/02/25
対応日

2004/02/25

*当ウイルスは、2004/02/18 18:44:04時点でアップデートされたウイルスパターンバージョンにて検出することが可能です。

種 類 ワーム
別 名 W32.Netsky.C@mm, WORM_NETSKY.C
対 象 Windows 95/98/Me/NT/2000/XP
危険度 最高
感染経路 電子メール, ネットワーク共有フォルダ
概 要

Win32.HLLM.Netsky.based(別名:NetSky.C)は感染したコンピュータで収集した電子メールアドレスへワームのコピーを添付した 電子メールを送信して感染拡大を試みるワームです。

詳 細

当ワームは重複して実行されることを防ぐため次のようなミューテックスを作成します。

[SkyNet.cz]SystemsMutex

ワームはWindowsフォルダに次のファイル名で当ワームのコピーを作成します。

Winlogon.exe

* Windowsフォルダは標準では、C:\Windows (Windows 95/98/Me/XP)またはC:\Winnt (Windows NT/2000)です。

Windows起動時にワームが自動的に実行されるように、次のようにレジストリを書き換えます。

HKEY_LOCAL_MACHINE\Software\Microsoft\

Windows\CurrentVersion\Run
ICQ Net = Windowsフォルダ\winlogon.exe -stealth

当ワームは次のようなレジストリを書き換えます。

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\

Windows\CurrentVersion\Run
Sentry
OLE
service
au.exe
d3dupdate.exe
DELETE ME
msgsvr32
Taskmon
Explorer
Windows Services Host

HKEY_CURRENT_USER\SOFTWARE\Microsoft\

Windows\CurrentVersion\RunServices
Sentry
OLE
service
au.exe
d3dupdate.exe
DELETE ME
msgsvr32
Taskmon
Explorer
Windows Services Host

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\

Windows\CurrentVersion\Run
KasperskyAV
System.

HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32

* Windowsシステムフォルダは標準では、C:\Windows\System (Windows 95/98/Me)、C:\Winnt\System32 (Windows NT/2000)またはC:\Windows\System32 (Windows XP)です。

当ワームはネットワーク共有フォルダに次のようなファイル名でワームのコピーを作成します。

1000 Sex and more.rtf.exe
3D Studio Max 3dsmax.exe
ACDSee 9.exe
Adobe Photoshop 9 full.exe
Adobe Premiere 9.exe
Ahead Nero 7.exe
Best Matrix Screensaver.scr
Clone DVD 5.exe
Cracks & Warez Archive.exe
Dark Angels.pif
Dictionary English - France.doc.exe
DivX 7.0 final.exe
Doom 3 Beta.exe
E-Book Archive.rtf.exe
Full album.mp3.pif
Gimp 1.5 Full with Key.exe
How to hack.doc.exe
IE58.1 full setup.exe
Keygen 4 all appz.exe
Learn Programming.doc.exe
Lightwave SE Update.exe
Magix Video Deluxe 4.exe
Microsoft Office 2003 Crack.exe
Microsoft WinXP Crack.exe
MS Service Pack 5.exe
Norton Antivirus 2004.exe
Opera.exe
Partitionsmagic 9.0.exe
Porno Screensaver.scr
RFC Basics Full Edition.doc.exe
Screensaver.scr 26KB
Serials.txt.exe 26KB
Smashing the stack.rtf.exe
Star Office 8.exe
Teen Porn 16.jpg.pif
The Sims 3 crack.exe
Ulead Keygen.exe
Virii Sourcecode.scr
Visual Studio Net Crack.exe
Win Longhorn Beta.exe
WinAmp 12 full.exe
Windows Sourcecode.doc.exe
WinXP eBook.doc.exe
XXX hardcore pic.jpg.exe

当ワームは感染したコンピュータにある次のような拡張子をもつファイルからメールアドレスを収集します。

.eml
.txt
.php
.pl
.htm
.html
.vbs
.rtf
.uin
.asp
.wab
.doc
.adb
.tbb
.dbx
.sht
.oft
.msg
.shtm
.cgi
.dhtm

当ワームは独自のSMTPを利用して収集したメールアドレスへワームのコピーを添付し、次のようなメールを 送信し感染拡大を試みます。

件名(次の中からランダムに選択):

Delivery Failed
Status
report
question
trust me
hey
Re: excuse me
read it immediatelly
hi
Re: does it?
Yep
important
hello
dear
Re: unknown
fake?
warning
moin
what's up?
info
Re: information
Here is it
stolen
private?
good morning
illegal...
error
take it
re:
Re: Re: Re: Re:
you?
something for you
exception
Re: hey
excuse me
Re: hi
Re: does it?
Re: important
Re: hello
believe me
Question
denied!
notification
Re: <5664ddff?$???2>
lol
last chance!
I'm back!
its me
notice!

本文(次の中からランダムに選択):

<Deliver Error>
<Message Error>
<Server Error>
what means that?
help attached
<...>
ok...
<Attachment from Poland>
that is interesting...
i wait for your comment about it.
such as yours?
read the details.
gonna?
here is the document.
*lol*
read it immediately!
i found that about you!
your hero in the picture?
yours?
here is it.
illegal st. of you?
is that true?
account?
is that your name?
picture?
message?
is that your account?
pwd?
I wait for an answer!
abuse?
is that yours?
you are a bad writer
I don't know your document!
<Mail failed>
I have your password!
you won the rk!
something about you!
classroom test of you?
kill the writer of this document!
old photos about you?
i hope thats not true!
your name is wrong!
does it match?
i found this document about you.
time to fear?
really?
do you know this????
i know your document!
did you sent it to me?
this file is bad!
why should I?
pages?
her.
another pic, have fun! ... :->
test it
child porn?
greetings
xxx ?
stuff about you?
your document is not good
something is going wrong!
your photo is poor
information about you?
the information is wrong!
doc about me?
kill him on the picture!
from the chatter (my photo!)
from your lover ;-)
love letter?
here, the serials
are you a teacherin the picture?
here, the introduction
is that criminal?
here, the cheats
i like your doc!
what do you think about it?
that's a funny text.
that's not the truth?
do you have?
instruct me about this!
i lost that
i am speachless about your document!
is that the reality?
reply
msg
your design is not good!
important?
your TAN number?
take it easy!
why?
you are naked in this document!
thats wrong!
your icq number?
i am desperate
modifications?
your personal record?
yes.
misc. and so on. see you!
your attachment? verify it.
you earn money, see the attachment!
is that your attachment?
is that your website?
you feel the same.
meaning of that?
possible?
you have tried to steal!
did you ask me for that?
you are bad
your job? (I found that!)
is that possible?
something is going ...
something is not ok
did you know from this document?
wrong calculation! (see the attachment!...
never!
poor quality!
good work!
excellent!
great!
i don't think so.
pretty pic about you?
docs?
schoolfriend?
<Warning from the Government>
<09580985869gj>
<?}
i want more...
here is the next one!
attachi#
did you see her already?
is that your wife?
is that your creditcard?
is that your photo?
do you think so?
do you have the bug also?
already?
forgotten?
drugs? ...
does it matter?
i have received this.
best?
the truth?
your body?
your eyes?
your face?
File is self-decryting.
File is damaged.
File is bad.
i saw you last week!
xxx service
your account is expired!
you cannot hide yourself! (see photo)
copyright?
what still?
who?
how?
<bad gateway>
only encrypted!
personal message!
my advice....
i've found it about you
<<<Failure>>>
<Attached Msg>
<scanned by norton antivirus>
great xxx!
man or women?
child or adult?
here is yours!
a crazy doc about you
xxx about you?
i don't want your xxx pics!
<Failed message available>
<Automailer>
doc?
trial?
what?
;-)
i need you!
correct it!
see this!
it's a secret!
this is nothing for kids!
it's so similar as yours!
is that your car?
do not give up!
great job!
here is the $%%454$
you are sexy in this doc!
incest?
let it!
you look like an ape!
you look like an rat?
be mad?
are you cranky?
bob the builder
did you know that?
money?
is that your car?
is this information about you?
is that your privacy?
is that your TAN?
is that your message?
is that your cd?
is that your finger?
your are naked?
is that your porn pic?
is that your work?
is that your family?
is that your beast?
is that your account?
is that your slip?
is that your domain?
are you the naked one?
are you the naked person!
are you the one?
does it belong to you?
do you have sex in the picture?
you have a sexy body in the pic!
your lie is going around the world!
<Transfer complete>
<Antispam complete>
lets talk about it!
do you know the thief?
are you a photographer?
you have done a mistake in the document...
its private from me
do not show this anyone!
new patch is available!
this is an attachment message!
in your mind?
Microsoft
fast food...
Your bill.
try this patch!
do you have an orgasm in the picture?
<Click the attachment to decrypt>
<Attachment Signature 34933920>
Transaction failed. Show the doc!
I 've found your bill!
see your name!
You are infected. Read the details!
here is my advice.
here is my photo!
here is the <censored>
feel free to use it.
does it belong to you?
Login required! Read the attachment!
your document is silly!
is the pic a fake?
Antispam is turned off. See file!
Authentification required. Read the att...
solve the problem!
<null>
do not use my document!
do not open the attachment!
do not visit the pages on the list I se...
explain!
tell me more about your document!
Your provider will be disabled!
Instant patches.

添付ファイル(次の中からランダムに選択):

document
associal
msg
yours
doc
wife
talk
message
response
creditcard
description
details
attachment
pic
me
trash
card
stuff
poster
posting
portmoney
textfile
moonlight
concert
sexy
information
news
note
number_phone
bill
mydate
swimmingpool
class_photos
product
old_photos
topseller
ps
important
shower
myaunt
aboutyou
yours
nomoney
birth
found
death
story
worker
mails
letter
more
website
regards
regid
friend
unfolds
jokes
doc_ang
your_stuff
location
454543403
final
schock
release
webcam
dinner
intimate stuff
sexual
ranking
object
secrets
mail2
attach2
part2
msg2
disco
freaky
visa
party
material
misc
nothing
transfer
auction
warez
undefinied
violence
update
masturbation
injection
naked1
naked2
tear
music
paypal
id
privacy
word_doc
image
incest

添付ファイルは .rtf.scr のように2つ拡張子を使用したファイル名になる場合があります。
また、添付ファイルはZIP形式に圧縮されている可能性があります。
添付ファイルの拡張子1(次の中からランダムに選択):

.txt
.rtf
.doc
.htm

添付ファイルの拡張子2(次の中からランダムに選択):

.exe
.scr
.com
.pif

駆除方法 ウイルスチェイサーでの検出及び駆除が可能です。
ウイルスチェイサーのアップデートを実行し、ウイルスチェイサーを最新の状態へアップデートして下さい。
メモリ&ブートセクタ検査を実行しワームが検出されましたら駆除して下さい。
すべてのファイルに対しウイルス検査を実行し、ワームとして検出されたファイルをすべて削除して下さい。
ワームによって変更されたレジストリを修正して下さい。
レジストリエディタは、画面左下にある「スタート」ボタンをクリックし、「ファイル名を指定して実行」を選択し、表示された画面に"regedit"と入力後、「OK」をクリックすると起動します。
参 照

当ウイルスはWin32.HLLM.Netsky.based

(別名:NetSky.B)の亜種です。