Global Sites
F-Secure.fi
F-Secure Italian site
F-Secure UK site
F-Secure.com
Slovenia
France
Germany
Italy
Japan
Sweden
F-Secure Virus Descriptions : NetSky.W
[Summary ] | [Disinfection ] | [Detailed Description ] | [Detection ]
NetSky.W worm variant was discovered on April 16th, 2004.
Although it has been just discovered, this variant is much more similar to
NetSky.P or NetSky.Q than to any of the later variants. In fact, its structure
bears a striking resemblance to that of NetSky.P, so only some differences among
them will be listed on this description.
This variant does not spread through P2P networks, as NetSky.P does.
F-Secure provides the special disinfection utility to eliminate
Netsky.W worm infection. You can download this utility from our
ftp site:
ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.exe
ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.zip
Disinfection instructions can be found here:
ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.txt
System administrators who are using F-Secure Policy Manager,
can distribute the tool as a JAR package automatically to all
workstations.
System administrators can download the JAR version from:
http://www.europe.f-secure.com/tools/f-netsky.jar
ftp://ftp.europe.f-secure.com/anti-virus/tools/f-netsky.jar
Installation to system
Upon execution Netsky.W copies itself as VisualGuard.exe file to the Windows
folder. The worm adds a startup key for itself into System Registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NetDy" = "%WinDir%\VisualGuard.exe"
where %WinDir% represents Windows folder name.
Additionally the worm drops the following files into Windows
folder:
zipped.tmp
base64.tmp
zip1.tmp
zip2.tmp
zip3.tmp
Email Spreading
Most of the email spreading functionality is similar or identical to NetSky.P.
Deleting Registry keys and disinfecting Bagle worm
NetSky.W worm removes Registry keys of several Bagle worm
variants if it finds them on an infected computer.
Detection of Netsky.W worm was published on April 16th, 2004 in
the following F-Secure Anti-Virus updates:
[FSAV_Database_Version]
Version=2004-04-16_03
Technical Details:
Alexey Podrezov & Ero Carrera, April 16th, 2004;
Description Updated:
Alexey Podrezov, April 28th, 2004;
F-Secure Corporation