|
Sunday, 25 September 2005 |
Description:
This worm propagates via email. It sends out copies of itself as an attachment to email messages using its own SMTP engine. It gathers target email addresses by searching all of an affected systems fixed drives for files with certain extensions. It can connect and submit a query for yahoo.com to a local DNS server. Once it finds a match, this worm also uses the said domain as its SMTP server.
It also spreads by dropping copies of itself in folders inside the Windows folder whose names contain the string SHAR.
This worms propagation techniques effectively ensure that it spreads to a good number of target machines.
Like other WORM_NETSKY variants, it seeks to prove that it is superior by deleting several registry keys to prevent the following malware from executing at every system startup:
* Variants of WORM_MYDOOM
* WORM_MIMAIL.T
* WORM_NETSKY.A
* WORM_NETSKY.B
|