F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : NetSky.W

[Summary] | [Disinfection] | [Detailed Description] | [Detection]



NAME:NetSky.W
ALIAS:W32/Netsky.W@mm, I-Worm.Netsky.o
SIZE:24064

Summary

NetSky.W worm variant was discovered on April 16th, 2004.

Although it has been just discovered, this variant is much more similar to NetSky.P or NetSky.Q than to any of the later variants. In fact, its structure bears a striking resemblance to that of NetSky.P, so only some differences among them will be listed on this description.

This variant does not spread through P2P networks, as NetSky.P does.

Disinfection

F-Secure provides the special disinfection utility to eliminate Netsky.W worm infection. You can download this utility from our ftp site:

ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.exe

ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.zip

Disinfection instructions can be found here:

ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.txt

System administrators who are using F-Secure Policy Manager, can distribute the tool as a JAR package automatically to all workstations.

System administrators can download the JAR version from:

http://www.europe.f-secure.com/tools/f-netsky.jar

ftp://ftp.europe.f-secure.com/anti-virus/tools/f-netsky.jar

Back to the Top


Detailed Description

Installation to system

Upon execution Netsky.W copies itself as VisualGuard.exe file to the Windows folder. The worm adds a startup key for itself into System Registry:

 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "NetDy" = "%WinDir%\VisualGuard.exe"

where %WinDir% represents Windows folder name.

Additionally the worm drops the following files into Windows folder:

 zipped.tmp
 base64.tmp
 zip1.tmp
 zip2.tmp
 zip3.tmp

Email Spreading

Most of the email spreading functionality is similar or identical to NetSky.P.

Deleting Registry keys and disinfecting Bagle worm

NetSky.W worm removes Registry keys of several Bagle worm variants if it finds them on an infected computer.


Back to the Top


Detection

Detection of Netsky.W worm was published on April 16th, 2004 in the following F-Secure Anti-Virus updates:

[FSAV_Database_Version]

Version=2004-04-16_03

Back to the Top


Technical Details: Alexey Podrezov & Ero Carrera, April 16th, 2004;

Description Updated: Alexey Podrezov, April 28th, 2004;

F-Secure Corporation