Spy Sweeper with AntiVirus

The most award-winning anti-spyware software

Spy Sweeper with Antivirus

Get serious about removing spyware with Spy Sweeper - the award-winning anti-spyware software trusted by millions of home computer users.

Add to Cart Button

$29.95

Spyware & Virus Directory

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 


VBS.Nightflight@mm

Risk Level 1: Very Low

Discovered: May 16, 2001
Updated: April 15, 2002 05:04:41 PM PDT
Also Known As: Bloodhound.VBS.Worm
Type: Worm
Infection Length: minimum 11,846 bytes

SUMMARY


VBS.Nightflight@mm is a polymorphic mass mailing worm written in the Visual Basic Scripting (VBS) language. The worm can email itself to all contacts in the Microsoft Outlook Address Book. It can also spread by network drives and it contains functionality such as changing the desktop wallpaper, spreading by mIRC, changing the Windows user information, and lowering security settings on the computer.

NOTE: Definitions dated May 16th or earlier will detect this as Bloodhound.VBS.Worm.

Protection

  • Virus Definitions (Intelligent Updater) May 16, 2001

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Moderate

Damage

  • Damage Level: Medium
  • Payload Trigger: On Fridays and Saturdays
  • Payload: On Fridays the desktop will be disabled and on Saturdays the Windows assistant Merlin will appear (if Microsoft Agent version 2 is installed)
  • Large Scale E-mailing: Attempts to email every one in the Microsoft Outlook Address Book
  • Degrades Performance: Since the worm can launch itself manyf times, it may cause a system slowdown
  • Compromises Security Settings: Lowers the Internet security settings on the computer

Distribution

  • Distribution Level: Medium
  • Subject of Email: HI :-)
  • Name of Attachment: The worm puts himself in the body of the email. There is therefor no attachment.
  • Shared Drives: Enumerates through mapped networkdrives

TECHNICAL DETAILS


When executed,VBS.Nightflight@mm does the following:
  1. It immediately adds itself as a value to the registry key

    HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun

    The value that the worm adds will have a polymorphic name, but it will always be seven characters with the first character in uppercase and the rest in lowercase. The Value Data of the entry will include the path to the Windows folder followed by help.txt.vbs%. This will occur every time that the worm is executed. Therefore, there may be many values in the Run key that start the worm. Here is an example:


  2. Next, the worm checks for the existence of the key HKEY_CURRENT_USERSoftwareNightflightsend.
    • If the key exists and has a Value Data of 1, the worm will go into an infinite loop. The purpose of this loop is to make sure that it does not get deleted from the system. If the worm is deleted, it will recreate itself.
    • If the key does not exist or does not have the value 1, the worm will perform all of its malicious actions.
  3. The worm starts by changing its own comments. This appears to be an attempt to make detection of the worm more difficult. However, the routine the worm uses is very simple. It just inserts random comments in random places. The worm does not remove the old comments, so every time this function is executed, it will increase the worm in size. The worm will also make an attempt to lower the security settings on the computer.

    NOTE:
    All variants of this worm are detected by the heuristics detection in Norton AntiVirus even with definitions dated prior to May 16th.
  4. The worm will then try to send itself to all contacts in the Microsoft Outlook Address Book. This worm contains a check, so it will not work with any client other than Microsoft Outlook.
  5. VBS.Nightflight@mm contains the functionality to spread using mIRC, a popular IRC client for Microsoft Windows. The worm will attempt to locate the Mirc.ini file, both locally and over mapped network drives. If the file is found, it will insert the Script.ini into the same folder as the Mirc.ini file. Once this occurs, the worm will be sent to other users over the IRC network as they join the network that you are using. It will also generate messages to other mIRC users when certain events occur; these messages will appear to have been sent by you.
  6. Next the worm will attempt to copy itself once into all folders on all mapped network drives that it can find.
  7. It will also attempt to change the desktop wallpaper. If the day is Friday, it will change a registry key so that all icons disappear from the Windows desktop, and the desktop becomes inaccessible. The worm will make add itself to the Windows registry so that when right-clicking anything, the option "Start the nightflight" will appear. If this option is selected, the worm will be executed.
  8. VBS.Nightflight@mm will change the registration information in the Windows registry, so the registration name will appear as Nightflight and the company name will be Carpe Noctem. Carpe Noctem appears to be a German band that plays black metal music; the first submission of this worm to SARC arrived from Germany.
  9. Next, if the day of the week is Saturday, the worm will check if Microsoft Agent version 2 is installed on the system. Specifically, the worm is looking for the presence of the Microsoft agent Merlin. If Merlin is found on the system, the worm will show him in a small window and have him say: "The Nightflight is still out there".
  10. Finally, the worm will enter the infinite loop that constantly checks so that the worm does not get deleted.

Recommendations

Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":

  • Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If they are removed, blended threats have less avenues of attack and you have fewer services to maintain through patch updates.
  • If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.
  • Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services (for example, all Windows-based computers should have the current Service Pack installed.). Additionally, please apply any security updates that are mentioned in this writeup, in trusted Security Bulletins, or on vendor Web sites.
  • Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.
  • Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.
  • Isolate infected computers quickly to prevent further compromising your organization. Perform a forensic analysis and restore the computers using trusted media.
  • Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.

REMOVAL


To remove this worm, delete files detected as VBS.Nightflight@mm, and undo the changes it made to the registry.

To remove the worm:
  1. Run LiveUpdate to make sure that you have the most recent virus definitions.
  2. Start Norton AntiVirus (NAV) and run a full system scan, making sure that NAV is set to scan all files.
  3. Delete any files detected as VBS.Nightflight@mm.

To edit the registry:

CAUTION: We strongly recommend that you back up the system registry before making any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure you modify only the keys specified. Please see the document How to back up the Windows registry before proceeding.
  1. Click Start, and click Run. The Run dialog box appears.
  2. Type regedit and then click OK. The Registry Editor opens.
  3. Navigate to the following key:

    HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun
  4. In the Name column of the right pane, look for and delete any values that have seven characters, with the first character in uppercase and the rest lowercase. The Value Data of the entry will include the path to the Windows folder followed by help.txt.vbs%. For example:


  5. Click Registry, and then click Exit



Spy Sweeper 5.2 stops spyware in its tracks while offering home computer users the ability to configure the program to suit their specific needs, such as:

Choose a Quick, Full or Custom Sweep: With Spy Sweeper 5.2, you can easily choose to perform a quick, full or customized sweep. If you're looking for an immediate diagnosis, choose a quick sweep. For a pinpointed search, customize your sweep to have Spy Sweeper skip files by folder or file extension. For a deep cleaning, opt for a full sweep.

Exclude Files from a Sweep: Spy Sweeper allows you to save time during a sweep by skipping specific files or different sections of your PC. You can select specific file extension, such as .xls or .mpg to exclude.

Additional Highlights

As soon as it's installed, Spy Sweeper gives 360 degrees of protection against spyware, including:

Simple Sweeps: Detecting spyware and removing unwanted programs found on your computer in three effortless steps

Easy Management: Quickly and simply configure program, sweep and upgrade options

Fast Home: Use the home screen to access the most commonly used functions of Spy Sweeper

Shields Summary: A redesigned shields summary page makes it simple to see at a glance which shields are on or off

Action Alerts: Receive clear, easy-to-understand notifications when new spyware threats are detected

"Spy Sweeper remains a favorite for protection from spyware."



"This program's dominance is apparent as soon as you install it."