| ALIAS: | W32/Netsky.W@mm, I-Worm.Netsky.o |
| SIZE: | 24064 |
Automatic Disinfection
Allow F-Secure Anti-Virus to disinfect the relevant files.
For more general information on disinfection, please see Removal Instructions.
Eliminating a Local Network Outbreak
If the infection is in a local network, please follow the instructions on this webpage:
Installation to system
Upon execution Netsky.W copies itself as VisualGuard.exe file to the Windows folder. The worm adds a startup key for itself into System Registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NetDy" = "%WinDir%\VisualGuard.exe"
where %WinDir% represents Windows folder name.
Additionally the worm drops the following files into Windows folder:
zipped.tmp base64.tmp zip1.tmp zip2.tmp zip3.tmp
Email Spreading
Most of the email spreading functionality is similar or identical to NetSky.P.
Deleting Registry keys and disinfecting Bagle worm
NetSky.W worm removes Registry keys of several Bagle worm variants if it finds them on an infected computer.