Re: I-Worm.NetSky.t

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Barry N. Wainwright (barry_at_barryw.net.INVALID)
Date: 04/08/04


Date: Thu, 08 Apr 2004 15:34:21 +0100

On 7/4/04 6:42 pm, in article
263a0b97.0404070942.41479184@posting.google.com, "Cyrus" <cyrus6@wanadoo.fr>
wrote:

> I am using microsoft Entourage on a Mac with OS X.3
>
> I know that I have a "I-Worm.NetSky.t" or some other king that is
> sending messages from my accounts, and I keep also getting messgaes
> with ".pif" attachments.
>
> I wnatd to know how can I find an remove this Worm from my computer.
>
> I appreciate your assistance.
>
> Best regards,
>
> Cyrus

Full details on the virus are found here:

<http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.t@mm.htm
l>

Note especially the bit that says:

> Systems Affected:
> Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server
> 2003, Windows XP

No mention of the Mac in there!

Macs are not affected, your computer is not infected.

It may appear that your computer is sending out these viruses, especially
when you get the bounces from bad addresses or systems that have rejected
the mail because it is infected. However, these emails are bneing sent out
by an infected windows machine, not yours. When an infected machine starts
sending viruses out, it will choose, at random, an email address stored on
the infected machine and will use this to forge the 'from' address and
return path. This way, the source of the infection is masked (to the
uninitiated) and is less likely to be identified and cleaned up.

The PIF files you are getting are likely from the same original source -
these are the infected emails being sent out by any one af a bazillion
windows viruses, including netsky. They are being sent to you because your
email address is listed in an infected computer's address book.

If one of the bounce backs returns the message with all headers intact it is
sometimes possible to trace the originating IP address from the routing
information. You can use any one of a dozen network look up tools to
identify the originating host, and so possibly the originating, infected,
machine. Then, you can send an email highlighting the URL posted above and
ask them to clean their act up.

-- 
Barry Wainwright
Microsoft MVP (see http://mvp.support.microsoft.com for details)
Seen the Entourage FAQ pages? - Check them out:
  <http://www.entourage.mvps.org/toc.html>
Please post responses to this newsgroup. If I ask you to contact me
off-list, remove '.INVALID' from email address before replying.


Relevant Pages

  • Re: Spam Problem
    ... except originating from the SBS server IP. ... outgoing emails in Exchange or SMTP logging, as the emails are sent via ... an SMTP engine on the infected machine. ... Cleaning up the infection is the next step. ...
    (microsoft.public.windows.server.sbs)
  • Re: Unexplained email sent (not spoofed), apparent Netsky
    ... date to allow infection by a downloaded email. ... When I ran my virus checker, ... >What makes you think that anything about the 'bounce' ... >> Since the outgoing mails seem to be really originating ...
    (microsoft.public.security.virus)
  • Updated mitigators and cleansing of Nimda
    ... Infection vectors; ... By browsing an infected webserver with Javascript execution ... Any infected machine which has mapped network ... TREND MICRO SCANMAIL FOR EXCHANGE 2000 -- SECOND to NONE ...
    (NT-Bugtraq)
  • RE: CodeBlue finally hitting, or what?
    ... Updated mitigators and cleansing of Nimda ... Infection vectors; ... Any infected machine which has mapped network ...
    (Incidents)
  • Re: Virus by e-mail : Swen
    ... The 'swen' worm running on an infected machine sent that e-mail. ... addresses it harvests from infected machine and networks. ... you can proof your system against infection, ...
    (microsoft.public.security.virus)