Skip Over Navigation Links
Center for Information TechnologyAntivirus
Antivirus Home Page
Contact Us
Questions or Comments
Disclaimers

Software
Current client downloads:
 VScan Engine/Dat (SuperDat) -5400/1158.5811
 VirusScan Enterprise 8.5i (with Patch 7) - Windows NT/2000/XP/2003
 Virex (OS X) Engine/Def - 7.2(v1.1)/081029
 Virex (OS 9.x) Engine/Def - 6.2/071001
 Linux & Solaris Engine/Dat - 5.2.00/4.0.5196
 Symantec Endpoint Protection 11.0 MR4
 Symantec Antivirus - 10.2
 Clean Boot 1.0
 Stinger v3.8.0 virus removal tool (Updated 09/10/07)
Current server downloads:
 VirusScan Enterprise 8.7i
 VirusScan Enterprise 8.5i
 NetShield NetWare - 4.6.2
 NetShield NetWare - 4.6.3
 NetShield NetWare Engine Update - 4.4.00
 ePO agent for NetWare
 ScanMail eManager - 3.0

Information
 Virex 7.x Installation Instructions
 VirusScan FAQs
 VirusScan Instructions
 Additional Resources

Archives
 List of Viruses

Virus Alerts

W32.Netsky.B@mm Last Updated 2/18/04 12:48pM

CIT has been notified of a new variant of the W32.Netsky.a@mm email virus called W32.Netsky.B@mm. This is a mass-mailing worm that also spreads via mapped network drives C through Z searching for folder names containing the word "Share" or "Sharing" used by P2P applications such as KaZaa. The email component searches for email addresses in files with the extentions .msg, .oft, .sht, .dbx, .tbb, .adb,.doc, .wab, .asp, .uin, .rtf, .vbs, .html, .htm, .pl, .php, .txt and .eml files. By using its own SMTP engine the worm sends copies of itself to all found contacts.

In email form, W32.Netsky.B@mm appears as follows:

From:(address is spoofed)

Subject:(one of the following)

  • hi
  • hello
  • read it immediately
  • something for you
  • warning
  • information
  • stolen
  • fake
  • unknown
The message body:(one of the following)

  • anything ok?
  • what does it mean?
  • ok
  • i'm waiting
  • read the details
  • here is the document
  • read it immediately!
  • my hero
  • here
  • is that true?
  • is that your name?
  • is that your account?
  • i wait for a reply!
  • is that from you?
  • you are a bad writer
  • I have your password!
  • something about you!
  • kill the writer of this document!
  • i hope it is not true!
  • your name is wrong
  • i found this document about you
  • yes, really?
  • that is bad
  • here it is
  • see you
  • greetings
  • stuff about you?
  • something is going wrong!
  • information about you
  • about me
  • from the chatter
  • here, the serials
  • here, the introduction
  • here, the cheats
  • that's funny
  • do you?
  • reply
  • take it easy
  • why?
  • thats wrong
  • misc
  • you earn money
  • you feel the same
  • you try to steal
  • you are bad
  • something is going wrong
  • something is fool

Attachment:(one of the following) ZIP file with double extension like .doc.pif, .rtf.com, .rtf.scr, .txt.exe (22,016 bytes )

  • document
  • msg
  • doc
  • talk
  • message
  • creditcard
  • details
  • attachment
  • me
  • stuff
  • posting
  • textfile
  • concert
  • information
  • note
  • bill
  • swimmingpool
  • product
  • topseller
  • ps
  • shower
  • aboutyou
  • nomoney
  • found
  • story
  • mails
  • website
  • friend
  • jokes
  • location
  • final
  • release
  • dinner
  • ranking
  • object
  • mail2
  • part2
  • disco
  • party
  • misc

NAI released Dat/SuperDat 4325 to detect and remove W32.Netsky.B@mm. The 4325 DAT/SuperDat is now available.

Symantec released 2/18/2004 virus definitions to detect and remove W32.Netsky.B@mm. Definitions are available through the LiveUpdate feature of Symantec Antivirus.

For more information see:

http://vil.nai.com/vil/content/v_101034.htm from NAI.
http://securityresponse1.symantec.com/sarc/sarc.nsf/html/w32.netsky.b@mm.html from Symantec.

This archive is not intended to be comprehensive. For a more complete virus library, please visit NAI's Virus Information Library at http://vil.nai.com.

Contact NIH Help Desk for assistance:
866-319-4357 (toll free), 301-496-4357 (6-HELP) (local), 301-496-8294 (TDD)
http://ithelpdesk.nih.gov/support
Register for iForgotMyPassWord

National Institutes of HealthCenter for Information Technology
National Institutes of Health
Bethesda, Maryland 20892

Questions or Comments | Disclaimers | Privacy Policy

Department of Health and Human ServicesHealth and Human Services
Washington, D.C. 20201
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -