
Netsky.ab Worm
Information
about Netsky.ab Worm:
Netsky.ab spreads
via e-mail and file sharing networks in
Windows platform. It collects e-mail
addresses stored in MSG, OFT, SHT, DBX,
TBB, ADB, DOC, WAB, ASP, UIN, RTF, VBS,
HTML, HTM, PL, PHP, TXT and EML files to
send infected messages. The message body,
subject and attachment name will be
randomly chosen by the worm.
When the infected
attachment is executed, the worm copies
itself to Windows folder as "services.exe".
The worm also creates new keys in the
registry Run section to load
automatically. The registry modification
is given below.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Service=C:\%Windows%\services.exe
Netsky worm
searches C to Z drives and drops infected
copy in the file sharing folders.
Removing
Netsky.ab worm from your computer:
Fire has
incorporated Netsky.ab worm in signature
file to protect Fire users from this worm
attack. Fire anti-virus users can update
this signature file by using online
update facility. It is available
with the registered version of Fire
anti-virus Kit.
A
free download
of FireLite
[ 1100 KB ]
version is also available to detect
Mydoom Worm. If you find this worm, use
registered version of Fire to remove. To
get the registered version of Fire call
us at 044-28170440 or mail to service@fireav.com
[Analysis:
Mr.Jacob Kalis, Prognet Technologies Pvt.
Ltd ]

|